Add PAN-OS 9.0 issues
This commit is contained in:
@@ -0,0 +1,265 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.0
|
||||
---
|
||||
|
||||
## WF500-4811
|
||||
|
||||
Fixed an issue where WF-500 appliances displayed the wrong WildFire® content version (show system info) after a WildFire content update.
|
||||
|
||||
## PAN-109668
|
||||
|
||||
A security related fix was made to limit the amount of information returned from an API call error message.
|
||||
|
||||
## PAN-109124
|
||||
|
||||
A security-related fix was made to address an issue where you were unable to retrieve GlobalProtect™ cloud service threat packet captures from the Logging Service on Panorama™ M-Series and virtual appliances.
|
||||
|
||||
## PAN-109096
|
||||
|
||||
Fixed an issue where the firewall did not remove the **4 Byte AS Format** number when **Remove Private AS** is enabled.
|
||||
|
||||
## PAN-109003
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) stopped responding during a local commit.
|
||||
|
||||
## PAN-107887
|
||||
|
||||
Fixed an issue where an API call did not return the details of the security policy when you added a service group.
|
||||
|
||||
## PAN-107779
|
||||
|
||||
Fixed an issue where Wildfire signature version information was no longer displayed after you activated a GlobalProtect client.
|
||||
|
||||
## PAN-107117
|
||||
|
||||
Fixed an issue where device administrators were unable to manually upload signature files (**Device** > **Dynamic Updates**) and the firewall displayed the following error message: Youneed superuser privileges to do that.
|
||||
|
||||
## PAN-106784
|
||||
|
||||
Fixed an issue where the firewall revealed password hashes in the web interface when changing administrator passwords.
|
||||
|
||||
## PAN-106721
|
||||
|
||||
Fixed an intermittent issue where a processor cache memory corruption caused a reload when the firewall freed packets from the buffer.
|
||||
|
||||
## PAN-106695
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where the Panorama management server enabled the administrator to clone a rule on the passive firewall.
|
||||
|
||||
## PAN-106331
|
||||
|
||||
Fixed an issue with multiple or overlapping custom URL categories where traffic matched the incorrect Security policy rule when the custom URL category was used in a Security policy rule with a URL filtering profile.
|
||||
|
||||
## PAN-106181
|
||||
|
||||
Fixed an issue where the **Cancel** option was removed to prevent access when you **Require Password Change on First Login** (**Device** > **Setup** > **Management**).
|
||||
|
||||
## PAN-106019
|
||||
|
||||
Fixed an issue where a process (routed) stopped responding when an incomplete command ran in the XML API.
|
||||
|
||||
## PAN-105849
|
||||
|
||||
A security-related fix was made to address an issue with the wf_curl.log file in WF-500 appliances (WildFire).
|
||||
|
||||
## PAN-105737
|
||||
|
||||
Fixed an issue where AUX ports remained in Down state after you upgraded to PAN-OS® 8.1.7.
|
||||
|
||||
## PAN-105684
|
||||
|
||||
Fixed as issue on a firewall in an HA active/passive configuration where OSPF and BGP running on an Aggregate Ethernet (AE) with LACP enabled took longer than expected after a failover.
|
||||
|
||||
## PAN-105040
|
||||
|
||||
Fixed an issue where the dataplane processor caused memory loss in the packet buffer pool.
|
||||
|
||||
## PAN-104623
|
||||
|
||||
Fixed an issue where a process (brdagent) printed QoS information messages in the brdagent.log file, which caused a missed heartbeat and the firewall to restart.
|
||||
|
||||
## PAN-104616
|
||||
|
||||
Fixed an issue where certificate imports failed when you used a backslash ( \ ) character in a password to export certificates.
|
||||
|
||||
## PAN-104578
|
||||
|
||||
```caveat
|
||||
PA-800 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where the HA failover took longer than expected.
|
||||
|
||||
## PAN-104572
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where the configd.log file displayed schema error messages after you created an administrator role with context switch UI permissions enabled.
|
||||
|
||||
## PAN-104354
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where the passive firewall ran a configuration out of sync after a restart.
|
||||
|
||||
## PAN-104078
|
||||
|
||||
Fixed an issue where administrators could not successfully add conditional advertisements (**Network** > **Virtual Routers** > **<virtual-router>** > **BGP** > **Conditional Adv**) for BGP routing tables (changes were lost after commit).
|
||||
|
||||
## PAN-103863
|
||||
|
||||
Fixed an issue where the IPSec tunnel restart (**Network** > **IPSec Tunnels** > **IKE Info**) did not display properly on the web interface.
|
||||
|
||||
## PAN-103857
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where the suspended firewall processed traffic.
|
||||
|
||||
## PAN-103615
|
||||
|
||||
Fixed an issue where scheduled log exports failed on nonstandard ports.
|
||||
|
||||
## PAN-103192
|
||||
|
||||
Fixed an issue on a firewall where the Global Find for IPSec tunnels displayed incorrect search results.
|
||||
|
||||
## PAN-103061
|
||||
|
||||
Fixed an issue where special characters contained in the CLI comment field caused the process (devsrvr) to stop responding.
|
||||
|
||||
## PAN-103055
|
||||
|
||||
Fixed an issue where you were unable to filter Address Groups (**Objects** > **Address Groups**) by an address object name.
|
||||
|
||||
## PAN-102779
|
||||
|
||||
Fixed an issue on a PA-3000 Series firewall where multiple (all_pktproc) processes failed and caused the dataplane to stop responding.
|
||||
|
||||
## PAN-102526
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where disk quota edits failed and displayed the following error message: quota-settings -> disk-quota is invalid.
|
||||
|
||||
## PAN-102029
|
||||
|
||||
Fixed an issue on a firewall where the DNS resolution routed through the dataplane and configured with a service route, stopped responding when the management interface was not configured.
|
||||
|
||||
## PAN-101821
|
||||
|
||||
Fixed an issue where Referer was spelled incorrectly in the HTTP Headers section of the Detailed Log View (**Monitor** > **URL Filtering**).
|
||||
|
||||
## PAN-101451
|
||||
|
||||
Fixed an issue where SNMP queries displayed incorrect values.
|
||||
|
||||
## PAN-101391
|
||||
|
||||
Fixed an issue where the scheduled nightly custom report was not generated or emailed as expected.
|
||||
|
||||
## PAN-101365
|
||||
|
||||
Fixed an intermittent issue where the session ID did not clear when the session ID is set to 0.
|
||||
|
||||
## PAN-101294
|
||||
|
||||
Fixed an issue where administrators were allowed to create tunnel interfaces from the template stack.
|
||||
|
||||
## PAN-101068
|
||||
|
||||
Fixed an issue where the object identifier (OID) ifAdminStatus incorrectly displayed up when configured to down.
|
||||
|
||||
## PAN-100656
|
||||
|
||||
Fixed an issue Panorama M-Series and virtual appliances where duplicate entries in BGP redistribution configurations were not verified, which caused commits to fail.
|
||||
|
||||
## PAN-100464
|
||||
|
||||
Fixed an issue where the sub-interfaces and the configurations were deleted when you tried to override the subinterface of a template stack.
|
||||
|
||||
## PAN-100154
|
||||
|
||||
Fixed an issue where the default static route always became the active route and took precedence over a DHCP auto-created default route that was pointing to the same gateway regardless of the metrics or order of installation. With this fix, the firewall no longer installs the default static route in the FIB when the system has both a DHCP auto-created default route and a manually configured default static route pointing to the same gateway.
|
||||
|
||||
## PAN-100049
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where Push Scope Selection (**Commit** > **Push to Devices**) selected firewalls not in the hierarchy of the firewall you selected.
|
||||
|
||||
## PAN-99945
|
||||
|
||||
Fixed an issue on Panorama where the progress bar in the web interface stopped responding and did not display any status after sending a commit or activating an auth code even though the task completed successfully.
|
||||
|
||||
## PAN-99640
|
||||
|
||||
A security-related fix was made to address a denial of service (DoS) vulnerability in PAN-OS Linux Kernel (CVE-2017-8890).
|
||||
|
||||
## PAN-99551
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where the User-ID™ process stopped responding on the passive firewall when the system was managing a high number of (more than 30,000) active users.
|
||||
|
||||
## PAN-99447
|
||||
|
||||
```caveat
|
||||
Virtual and M-Series Panorama appliances and Log Collectors only
|
||||
```
|
||||
|
||||
") Fixed an issue where a Log Collector received logs destined for closed Elasticsearch (ES) indices, which caused indices to return failure messages and, when the issue persisted for more than a few hours, caused Log Collectors to disconnect and reconnect repeatedly when attempting (and failing) to process the re-queued logs.
|
||||
|
||||
## PAN-98130
|
||||
|
||||
Fixed an intermittent issue where the firewall allowed traffic based on an unmatched rule after a session rematch is triggered.
|
||||
|
||||
## PAN-98005
|
||||
|
||||
Fixed an issue where adding more than eight Log Collectors to a collector group caused the configuration (configd) process to stop responding.
|
||||
|
||||
## PAN-97848
|
||||
|
||||
Fixed an issue where if you deployed Panorama on KVM, it deployed in Legacy mode instead of Management Only mode even when meeting the minimum resource requirements for Management Only mode.
|
||||
|
||||
## PAN-97417
|
||||
|
||||
Fixed an issue where the loopback IP address redistributed to the Local RIB table instead of the Adj-RIBs-out table.
|
||||
|
||||
## PAN-96344
|
||||
|
||||
Fixed an issue on a firewall where TCP reset packets were sent even after you set the vulnerability profile action to drop the packets.
|
||||
|
||||
## PAN-96297
|
||||
|
||||
Fixed an issue where a process (useridd) stopped responding due to the syslog server messages not parsing with field identifiers.
|
||||
|
||||
## PAN-95445
|
||||
|
||||
```caveat
|
||||
This fix requires the VMware NSX 2.0.4 or a later plugin.
|
||||
```
|
||||
|
||||
Fixed an issue where VM-Series firewalls for NSX and firewalls in an NSX notify group (**Panorama** > **VMware NSX** > **Notify Group**) briefly dropped traffic while receiving dynamic address updates after the primary Panorama in a high availability (HA) configuration failed over.
|
||||
|
||||
## PAN-94486
|
||||
|
||||
Fixed an issue where the dataplane did not get a dynamic IP address assigned because the process (routed) did not release it.
|
||||
|
||||
## PAN-92725
|
||||
|
||||
Fixed an issue on the firewall and Panorama management server where the web interface became unresponsive because the (cord) process restarted after you configured multiple log forwarding destinations in a single forwarding rule for Correlation logs (**Device** > **Log Settings**).
|
||||
|
||||
## PAN-92485
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to set the MTU (**Network** > **Interfaces** > **Ethernet** > **<Interface>** > **Ethernet Interface** > **Advanced** > **Other Info**) value to more than 1460 bytes with Jumbo Frames enabled.
|
||||
|
||||
## PAN-91930
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where you were unable to type in tunnel zone names in the Tunnel Source Zone (**Policies >** > **Pre Rules >** > **<rule-name>** > **Inspection** > **Security Options**) field.
|
||||
|
||||
## PAN-91499
|
||||
|
||||
Fixed an issue on a firewall where an address object FQDN resolution returned the IPv6 DNS record but did not return all associated -- IPv4 and IPv6 -- DNS records.
|
||||
|
||||
## PAN-91442
|
||||
|
||||
Fixed an issue where an external dynamic list with an invalid IPv6 address range caused commits to fail.
|
||||
|
||||
## PAN-82278
|
||||
|
||||
Fixed an issue where filtering did not work for Threat logs when you filtered for threat names that contained certain characters: single quotation (’), double quotation (”), back slash (\), forward slash (/), backspace (\b), form feed (\f), new line (\n), carriage return (\r), and tab (\t).
|
||||
|
||||
## PAN-72861
|
||||
|
||||
Fixed an issue where when you configured a PA-5200 Series or PA-7000 Series firewall to perform tunnel-in-tunnel inspection, which includes GRE keep-alive packets (**Policies** > **Tunnel Inspection** > **<tunnel_inspection_rule>** > **Inspection** > **Inspect Options**), and ran the clear session all CLI command while traffic was traversing a tunnel, the firewall temporarily dropped tunneled packets.
|
||||
@@ -0,0 +1,505 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.10
|
||||
---
|
||||
|
||||
## PAN-152699
|
||||
|
||||
Fixed an issue where the firewall added a redundant 0\r\n packet while processing Clientless VPN traffic.
|
||||
|
||||
## PAN-151197
|
||||
|
||||
Fixed an issue where a process (authd) restarted when an administrator authenticated to the firewall with an Active Directory (AD) account. This issue occurred when LDAP was configured with FQDN, used DHCP instead of a static management IP address, and used the management interface to connect to the LDAP server.
|
||||
|
||||
## PAN-150172
|
||||
|
||||
Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
|
||||
## PAN-150170
|
||||
|
||||
```caveat
|
||||
and PAN-149822
|
||||
```
|
||||
|
||||
A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)).
|
||||
|
||||
## PAN-150013
|
||||
|
||||
```caveat
|
||||
and PAN-149822
|
||||
```
|
||||
|
||||
A fix was made to address an OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allowed authenticated administrators to disrupt system processes and execute arbitrary code and OS commands with root privileges ([CVE-2020-2000](https://security.paloaltonetworks.com/CVE-2020-2000)).
|
||||
|
||||
## PAN-149839
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Added CLI commands to enable/disable resource-control groups and CLI commands to set an upper memory limit of 8G on a process (mgmtsrvr). To enable resource-control groups, use debug software resource-control enable and to disable them, use debug software resource-control disable. To set the memory limit, use debug management-server limit-memory enable, and to remove the limit, use debug management-server limit-memory disable. For the memory limit change to take effect, the firewall must be rebooted.
|
||||
|
||||
## PAN-149813
|
||||
|
||||
Fixed an issue where the reply to an XML API call from Panorama was in a different format after upgrading to PAN-OS 8.1.14-h1 and later releases, which caused automated systems to fail the API call.
|
||||
|
||||
## PAN-149325
|
||||
|
||||
Fixed an issue on Panorama where the web interface took more time than expected to load changes when the virtual router was large or when there was a large configuration change request from the web interface.
|
||||
|
||||
## PAN-149005
|
||||
|
||||
Fixed an issue where XML API failed to fetch logs larger than 10MB.
|
||||
|
||||
## PAN-148806
|
||||
|
||||
A fix was made to address an uncontrolled resource consumption vulnerability in PAN-OS that allowed for a remote unauthenticated user to upload temporary files through the management web interface that were not properly deleted after the request was finished. An attacker could disrupt the availability of the management web interface by repeatedly uploading files until available disk space was exhausted ([CVE-2020-2039](https://security.paloaltonetworks.com/CVE-2020-2039)).
|
||||
|
||||
## PAN-148676
|
||||
|
||||
Fixed an issue where the panlogs directory reached 100% utilization on the firewall due to early calculation of the .size file.
|
||||
|
||||
## PAN-148522
|
||||
|
||||
Fixed an issue for PAN-DB where certain situations caused performance issues.
|
||||
|
||||
## PAN-147996
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Fixed a buffer overflow issue.
|
||||
|
||||
## PAN-147424
|
||||
|
||||
Fixed an issue with internal buffer and file sizes where logs were discarded due to slow log purging when the incoming log rate was high.
|
||||
|
||||
## PAN-147399
|
||||
|
||||
Fixed an issue where Panorama in Legacy mode rebooted due to multiple process (reportd) restarts.
|
||||
|
||||
## PAN-147258
|
||||
|
||||
Fixed an issue with one-way audio for inbound voice calls due to incorrect source port translation.
|
||||
|
||||
## PAN-147203
|
||||
|
||||
Fixed an issue where API calls did not return the output for the operational command for running configurations.
|
||||
|
||||
## PAN-146837
|
||||
|
||||
A fix was made to address a vulnerability involving information exposure through log files where sensitive fields were recorded in the configuration log without masking on PAN-OS software when the after-change-detail custom syslog field was enabled for configuration logs and the sensitive field appeared multiple times in one log entry. The first instance of the sensitive field was masked but subsequent instances were left in clear text ([CVE-2020-2043](https://security.paloaltonetworks.com/CVE-2020-2043)).
|
||||
|
||||
## PAN-146624
|
||||
|
||||
Fixed an issue where exporting logs from the web interface did not generate a system log entry.
|
||||
|
||||
## PAN-145942
|
||||
|
||||
After upgrading to certain PAN-OS 8.1 and 9.0 versions, for certain configurations using dynamic routing without graceful restart and with Bidirectional Forwarding Detection (BFD) enabled, there was a longer traffic hit after a high availability (HA) failover compared to previous versions. This was due to BFD incorrectly timing admin-down messages for the failover event.
|
||||
|
||||
## PAN-145929
|
||||
|
||||
Fixed an issue where, after upgrading the passive firewall, the stream control transmission protocol (SCTP) sessions synced from the active firewall did not retain the rule information, and, after failover, SCTP stateful inspection did not work.
|
||||
|
||||
## PAN-145507
|
||||
|
||||
Fixed an issue on the firewalls where traffic originating from a GlobalProtect user did not match host information profile (HIP) based Security policies using the cached HIP report. Instead, the traffic was denied until the GlobalProtect agent submitted a new HIP report about 20 seconds later.
|
||||
|
||||
## PAN-145422
|
||||
|
||||
Fixed an issue where a process (all_pktproc) restarted while processing SSL VPN sessions.
|
||||
|
||||
## PAN-145305
|
||||
|
||||
Fixed an issue where an inconsistent PAN-DB cloud connection caused the firewall to negotiate the incorrect version and decode the cloud responses with the incorrect format.
|
||||
|
||||
## PAN-145302
|
||||
|
||||
Fixed an issue where the HA peer device did not preserve its import configuration when the mode was active/active and VR sync was disabled.
|
||||
|
||||
## PAN-145142
|
||||
|
||||
Fixed an issue where Panorama running 9.0.8 allowed a user with the admin role Device Group and Template to create templates and template stacks.
|
||||
|
||||
## PAN-145041
|
||||
|
||||
Fixed an issue on the firewalls where a process (all_task) stopped responding.
|
||||
|
||||
## PAN-144804
|
||||
|
||||
Fixed an issue where the firewall generated GPRS tunneling protocol (GTP) logs for invalid GTP packets. This fix also implements a counter, flow_gtp_invalid_ver, where the invalid packets are counted.
|
||||
|
||||
## PAN-144670
|
||||
|
||||
Fixed an issue where the multi-factor authentication (MFA) timestamp was not redistributed across the virtual system (vsys) when the IP address-to-user mapping type was UIA.
|
||||
|
||||
## PAN-144613
|
||||
|
||||
Fixed an issue where, when previewing device group configurations from Panorama, the following error message was returned: Parameter device group missing.
|
||||
|
||||
## PAN-144492
|
||||
|
||||
Fixed an issue where traffic matched an incorrect URL filtering profile due to a similarity in the MD5 hashes between the URL filtering profiles.
|
||||
|
||||
## PAN-144232
|
||||
|
||||
Fixed an issue where, when any change was made to an authentication profile, the LDAP server or local user database in a shared context removed the user group mapping information from the firewall.
|
||||
|
||||
## PAN-143686
|
||||
|
||||
Fixed an issue where a firewall running in FIPS mode was unable to download the GlobalProtect datafile even when a GlobalProtect license was installed and valid.
|
||||
|
||||
## PAN-143644
|
||||
|
||||
Fixed an issue in multi-vsys firewalls where traffic did not match an FQDN address group based policy.
|
||||
|
||||
## PAN-143493
|
||||
|
||||
Fixed an memory issue associated with a process (mgmtsrvr) due to a large number of ACK packets in logs on Panorama or the log collector.
|
||||
|
||||
## PAN-143442
|
||||
|
||||
Fixed an issue where Amazon Web Services (AWS) Nitro System based VM-Series firewalls unexpectedly rebooted due to input/output (I/O) errors caused by improper NMVE I/O timeout settings.
|
||||
|
||||
## PAN-142927
|
||||
|
||||
Fixed an issue where the locked users list grew too large, which caused 100% CPU usage on a process (authd). With this fix, locked users will be purged hourly if the lockout time for that user has expired.
|
||||
|
||||
## PAN-142853
|
||||
|
||||
Fixed an issue on Panorama where commits failed, referring to a portion of the configuration that was not changed.
|
||||
|
||||
## PAN-142674
|
||||
|
||||
Fixed an issue where a process (brdagent) failed in an HA configuration using High Speed Chassis Interconnect (HSCI) ports due to a memory leak.
|
||||
|
||||
## PAN-142363
|
||||
|
||||
Fixed an issue where a process (*mprelay*) stopped responding and invoked an out-of-memory (OOM) killer condition and displayed the following error messages: `tcam full` and `pan_plfm_fe_cp_arp_delete`.
|
||||
|
||||
## PAN-142302
|
||||
|
||||
Fixed an issue where the firewalls faced connection issues with Cortex Data Lake.
|
||||
|
||||
## PAN-142089
|
||||
|
||||
Fixed an internal logging issue for a daemon (authd).
|
||||
|
||||
## PAN-141844
|
||||
|
||||
Fixed an issue where promiscuous VLAN mode did not work with the new host drivers being used on the ESXi and single-root input/output virtualization (SR-IOV) with VLAN tagging did not work as expected. Both Data Plane Development Kit and packet mmap mode did not work.
|
||||
|
||||
## PAN-141239
|
||||
|
||||
Fixed an issue where dataplane free memory was depleted, which affected new GlobalProtect connections to the firewall.
|
||||
|
||||
## PAN-141221
|
||||
|
||||
Fixed an issue where a commit or content update operation with an error was not prevented from executing in the dataplane, which caused corruption in the dataplane policy cache.
|
||||
|
||||
## PAN-141099
|
||||
|
||||
Fixed an issue where the HTTP/2 stream method was no longer valid after overloading the same pointer to point to either the HTTP/2 stream or the proxy flow.
|
||||
|
||||
## PAN-140982
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where a process (mprelay) on the control plane was restarted due to an internal heartbeat miss.
|
||||
|
||||
## PAN-140747
|
||||
|
||||
Fixed an issue where the firewall failed to establish SFTP firewall-server connections when SSH decryption was enabled.
|
||||
|
||||
## PAN-140389
|
||||
|
||||
Fixed an issue on Panorama in Legacy mode where configuring Network File System (NFS) log storage (**Device > Setup > Operations**) caused all plugin installations to fail.
|
||||
|
||||
## PAN-140375
|
||||
|
||||
Fixed an issue where a process (logrcvr) exited due to a race condition.
|
||||
|
||||
## PAN-139365
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Enhanced latency-sensitive protocols processing. With this fix, the following latency-sensitive control traffic will be prioritized: BGP, BFD, LACP, OSPF, OSPFv3, Protocol Independent Multicast (PIM), and Internet Group Management Protocol (IGMP).
|
||||
|
||||
## PAN-139264
|
||||
|
||||
Fixed an issue where the Elasticsearch cluster status displayed in yellow due to a missing replica serial number.
|
||||
|
||||
## PAN-139172
|
||||
|
||||
Fixed an issue where response pages generated from the firewall used the SMAC and DMAC addresses from the original packet, which caused a MAC flap on connected switches.
|
||||
|
||||
## PAN-138584
|
||||
|
||||
Fixed an issue that prevented the addition of a secondary logging disk for a VM-Series firewall deployed on AWS using Nitro server instance types.
|
||||
|
||||
## PAN-138037
|
||||
|
||||
Fixed an issue where the host information profile (HIP) match message was automatically enabled when modifying the GlobalProtect Agent settings.
|
||||
|
||||
## PAN-138034
|
||||
|
||||
Fixed an issue where virtual machine (VM) information source Dynamic Address Groups overrode static address groups, which caused traffic to hit the wrong Security policy rule.
|
||||
|
||||
## PAN-137885
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Microsoft Azure environment only
|
||||
```
|
||||
|
||||
Fixed an issue where a firewall with accelerated networking enabled was unable to process packets efficiently because of underlying Microsoft drivers. To leverage this fix, you must upgrade to VM-Series Plugin 1.0.12.
|
||||
|
||||
## PAN-137656
|
||||
|
||||
Fixed an issue where the show config diff CLI command did not work correctly and produced unexpected output.
|
||||
|
||||
## PAN-136957
|
||||
|
||||
Fixed an issue where access was denied if a password contained more than 63 characters.
|
||||
|
||||
## PAN-136950
|
||||
|
||||
Fixed an issue where, on a firewall managed by Panorama, the XML API based IP tags were lost after a firewall reboot or process (**useridd**) restart.
|
||||
|
||||
## PAN-136844
|
||||
|
||||
Fixed an issue for S11 traffic where if the Modify Bearer Request message came after 30 seconds of Create Session Response message, the firewall dropped the Modify Bearer Request packet. This fix increases this time to 90 seconds.
|
||||
|
||||
## PAN-136726
|
||||
|
||||
Fixed an issue on the firewall where the dataplane pan-task process (all_pktproc) stopped responding while inspecting Server Message Block (SMB) traffic.
|
||||
|
||||
## PAN-136623
|
||||
|
||||
Fixed an issue where a process (useridd) failed due to internal user groups that were loading from the disk taking over the lock.
|
||||
|
||||
## PAN-136304
|
||||
|
||||
Fixed an issue where clientless VPN rewrite failed due to incorrect parsing of the HTML webpage.
|
||||
|
||||
## PAN-135946
|
||||
|
||||
Fixed an intermittent issue where Panorama was unable to query logs from the log collector due to large file sizes in es_cache_cron.log.
|
||||
|
||||
## PAN-135547
|
||||
|
||||
Fixed an issue on Panorama where administrators were unable to delete a shared address object even when it was not referenced in the configuration.
|
||||
|
||||
## PAN-135418
|
||||
|
||||
Fixed an issue on the firewall where configuring uppercase **User Domain** values in authentication profiles led to a failure in GlobalProtect Agent configuration selection based on the domain user match condition.
|
||||
|
||||
## PAN-135356
|
||||
|
||||
Fixed an issue where policies that contained objects did not display correctly when exported to CSV or PDF format.
|
||||
|
||||
## PAN-135354
|
||||
|
||||
Fixed an issue where the paths between the control plane and the dataplanes in network processing cards (NPCs) stalled in the dataplane-to-control plane direction due to the Ring Descriptor entries becoming out of sync on each side. This produced unrecoverable data path monitoring failures, which caused the chassis to become nonfunctional.
|
||||
|
||||
## PAN-135321
|
||||
|
||||
Fixed an issue where all NAT rules using the same FQDN entries as translated IP addresses were not updated when the IP addresses changed for those FQDNs.
|
||||
|
||||
## PAN-135262
|
||||
|
||||
A fix was made to address a vulnerability involving information exposure through log files where an administrator's password or other sensitive information was logged in cleartext while using the CLI in PAN-OS software. The opcmdhistory.log file was introduced to track operational command (op-command) usage but did not mask all sensitive information ([CVE-2020-2044](https://security.paloaltonetworks.com/CVE-2020-2044)).
|
||||
|
||||
## PAN-135158
|
||||
|
||||
Fixed an issue where setting an IPv6 destination filter for the packet-diag option returned an error regarding a character limit.
|
||||
|
||||
## PAN-135134
|
||||
|
||||
Fixed an issue where using a session_proxy() without checking that it actually is a proxy led to a dataplane process restart.
|
||||
|
||||
## PAN-134981
|
||||
|
||||
Fixed an issue with a memory leak in a process (user-id) due to failed LDAP over SSL (LDAPS) requests.
|
||||
|
||||
## PAN-134810
|
||||
|
||||
Fixed an issue where **Resolve (Objects > Addresses > <Name>)** in the web interface did not work for FQDN address objects with more than 63 characters.
|
||||
|
||||
## PAN-134714
|
||||
|
||||
Fixed an issue where Safe Search was not enabled after an application change.
|
||||
|
||||
## PAN-134624
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the VLAN interface failed to obtain the MAC address when the interface was used as a DHCP relay agent.
|
||||
|
||||
## PAN-134488
|
||||
|
||||
Fixed an issue where a process (all_pktproc) restarted while processing Clientless VPN traffic.
|
||||
|
||||
## PAN-134038
|
||||
|
||||
Fixed an issue where custom signatures did not properly detect the User-Agent header when the Origin header was above the User-Agent header.
|
||||
|
||||
## PAN-133915
|
||||
|
||||
Fixed an issue on Panorama where configuring a BGP import rule from the CLI failed with the following error message: Server error : permission denied for the command set.
|
||||
|
||||
## PAN-133912
|
||||
|
||||
Fixed an issue where querying traffic logs based on address objects and address groups did not work.
|
||||
|
||||
## PAN-133880
|
||||
|
||||
Fixed an issue where RADIUS authentication failed due to an FQDN resolution failure after the VM-Series firewall rebooted.
|
||||
|
||||
## PAN-133673
|
||||
|
||||
Fixed an issue that caused a procses (ikemgr) to exit when site-to-site VPNs experienced connectivity interruptions.
|
||||
|
||||
## PAN-133609
|
||||
|
||||
Fixed an issue where the Authentication Portal did not work due to a large number of HTTP requests with unsupported Authorization headers.
|
||||
|
||||
## PAN-133285
|
||||
|
||||
Fixed an issue on the firewalls where configuring a default Online Certificate Status Protocol (OCSP) URL in front of an intermediate certificate authority (CA) in a certificate profile did not override the OCSP URL during the validation of client certificates issued by the intermediate CA.
|
||||
|
||||
## PAN-132922
|
||||
|
||||
Fixed an issue where service objects were unable to be deleted if they were configured to exceed firewall limits.
|
||||
|
||||
## PAN-132715
|
||||
|
||||
Fixed an issue where a child dynamic address group was not added as a member of the parent group.
|
||||
|
||||
## PAN-132697
|
||||
|
||||
Fixed an issue where the GlobalProtect portal did not generate certificate signing requests (CSRs) due to failed Simple Certificate Enrollment Protocol (SCEP) authentication cookie validation.
|
||||
|
||||
## PAN-131973
|
||||
|
||||
Fixed an issue where both firewalls in an HA active/passive configuration stopped responding at the same time.
|
||||
|
||||
## PAN-131814
|
||||
|
||||
Fixed an issue where the firewall did not recognize a device when the DHCP contained a hostname with a trailing NULL.
|
||||
|
||||
## PAN-131491
|
||||
|
||||
Fixed an issue where the **ACC** risk meter displayed as zero for long time periods with a large amount of logs.
|
||||
|
||||
## PAN-131045
|
||||
|
||||
Fixed an issue where a rare cleartext HTTP/2 application behavior caused a resource leak. If jumbo frames were enabled, this leak caused the App-ID queue to fill up quickly, which led to legitimate sessions being discarded.
|
||||
|
||||
## PAN-130564
|
||||
|
||||
Fixed an issue where the session ID did not display correctly in the debug logs related to the hardware security module (HSM).
|
||||
|
||||
## PAN-130562
|
||||
|
||||
Fixed an issue where, in VM-Series firewalls deployed using init-cfg.txt in the bootstrap process and set in an HA configuration, the configuration did not display as synchronized due to the initcfg configuration.
|
||||
|
||||
## PAN-130168
|
||||
|
||||
Fixed an issue where a process (pan_comm) stopped responding due to operation commands run during a commit.
|
||||
|
||||
## PAN-129474
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) restarted due to race conditions initialized by the mutex.
|
||||
|
||||
## PAN-129461
|
||||
|
||||
Fixed an issue where excessive next hop FPGA exceptions occurred when an ARP request or response was lost in the network in an ECMP configuration, which blocked subsequent ARP learning due to a full queue.
|
||||
|
||||
## PAN-129294
|
||||
|
||||
Fixed an issue on Panorama where the **Policy Optimizer** showed invalid data for **Rule Usage**.
|
||||
|
||||
## PAN-129277
|
||||
|
||||
Enhanced a daemon (dnsproxy) to support DNS compression for query strings.
|
||||
|
||||
## PAN-128761
|
||||
|
||||
A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2037](https://security.paloaltonetworks.com/CVE-2020-2037)).
|
||||
|
||||
## PAN-128650
|
||||
|
||||
Fixed an issue where selecting **Preview Changes** under a specific device group resulted in the following error message: Parameter device group missing.
|
||||
|
||||
## PAN-128042
|
||||
|
||||
Fixed an issue where the dynamic address group failed due to a process (devsrvr) not being synced with another process (useridd).
|
||||
|
||||
## PAN-127691
|
||||
|
||||
Fixed an issue where the dataplane maintained the old category for the URL even after changing or deleting that category from PAN-DB.
|
||||
|
||||
## PAN-126938
|
||||
|
||||
Fixed an issue where multiple daemons restarted due to MP ARP overflow.
|
||||
|
||||
## PAN-126353
|
||||
|
||||
Fixed an issue where the XML API used to retrieve hardware status periodically failed with a 200 OK message and no data.
|
||||
|
||||
## PAN-120530
|
||||
|
||||
Fixed an issue where a Panorama appliance running PAN-OS 10.0.0 observed restarts in a process (reportd) while running a custom report when the log collector or remote device was running a software version earlier than the current version on Panorama.
|
||||
|
||||
## PAN-120249
|
||||
|
||||
Fixed an issue where Elasticsearch failed to properly start up, which caused issues with logging on Panorama or the Log Collector.
|
||||
|
||||
## PAN-118468
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on VMware ESXi only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall stays in a boot loop and enters maintenance mode after adding a 60GB disk.
|
||||
|
||||
## PAN-118416
|
||||
|
||||
```caveat
|
||||
Japanese language only
|
||||
```
|
||||
|
||||
Fixed an issue where the **WildFire Update Schedule** incorrectly displayed At as Atlantic.
|
||||
|
||||
## PAN-116843
|
||||
|
||||
Fixed an issue on Panorama where, when navigating through **Policies**, the following error message displayed: show rule hit count op-command failed.
|
||||
|
||||
## PAN-115954
|
||||
|
||||
Fixed an issue where commits failed with the following error: Error unserializing profile objects failed to handle CONFIG_UPDATE_START.
|
||||
|
||||
## PAN-113523
|
||||
|
||||
Fixed an intermittent issue where configuration audit stopped showing commit history and revisions.
|
||||
|
||||
## PAN-112539
|
||||
|
||||
Fixed an issue where the firewall stopped forwarding logs to the log collector from the Log Processing Card (LPC) after a commit push from Panorama due to a race condition.
|
||||
|
||||
## PAN-112246
|
||||
|
||||
Fixed an issue on the firewalls where a process (mgmtsrvr) restarted after the Panorama connection flapped.
|
||||
|
||||
## PAN-101484
|
||||
|
||||
A fix was made to address an OS command injection vulnerability in the PAN-OS management interface that allowed authenticated administrators to execute arbitrary OS commands with root privileges ([CVE-2020-2038](https://security.paloaltonetworks.com/CVE-2020-2038)).
|
||||
@@ -0,0 +1,257 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.12
|
||||
---
|
||||
|
||||
## PAN-158691
|
||||
|
||||
Fixed an issue with GPRS tunneling protocol (GTP) event packet capture (pcap) where enabling **Packet Capture** did not work.
|
||||
|
||||
## PAN-155053
|
||||
|
||||
Fixed an issue where user information in the Clientless VPN wasn't handled properly in high availability (HA) configurations, which resulted in the firewall being unable to create more user sessions.
|
||||
|
||||
## PAN-154323
|
||||
|
||||
Fixed an issue in Panorama where frequent API requests caused the Panorama web interface to become unresponsive. This issue occurred because the web interface automatically refreshed after each request.
|
||||
|
||||
## PAN-154114
|
||||
|
||||
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where secrets in PAN-OS XML API requests were logged in cleartext in the web server logs when the API was used incorrectly ([CVE-2021-3036](https://security.paloaltonetworks.com/CVE-2021-3036)).
|
||||
|
||||
## PAN-153440
|
||||
|
||||
Fixed an issue where firewalls repeatedly connected and disconnected to Cortex Data Lake due to a probing issue.
|
||||
|
||||
## PAN-153107
|
||||
|
||||
Fixed an issue where a dataplane process stopped responding while processing fragmented traffic on GTP-U tunnels.
|
||||
|
||||
## PAN-152912
|
||||
|
||||
Fixed an issue where a content update caused the Panorama XML cache build to fail. This resulted references of the used objects on Panorama being removed, which caused commits on the managed firewalls to fail.
|
||||
|
||||
## PAN-152746
|
||||
|
||||
Fixed an issue where the firewall dropped GTPv2-x Create Session Response packets with the following error message: bad port 84b.
|
||||
|
||||
## PAN-152440
|
||||
|
||||
Fixed an issue where the syntax on GlobalProtect DNS suffixes was not validated.
|
||||
|
||||
## PAN-152282
|
||||
|
||||
Fixed an issue where platforms using AHO for content and application inspection ran into dataplane process (all_pktproc) restarts.
|
||||
|
||||
## PAN-151486
|
||||
|
||||
Fixed an issue where user activity reports failed to run when the firewall was in FIPS mode.
|
||||
|
||||
## PAN-151483
|
||||
|
||||
Fixed an issue where, when an out-of-order stream of TCP packets was subjected to HTTP header insertion, the packets were duplicated.
|
||||
|
||||
## PAN-151149
|
||||
|
||||
Fixed an issue where certificates, custom logos, and Security Assertion Markup Language (SAML) metadata were unable to be uploaded from the web interface using a Chromium-based browser running version 84 or later.
|
||||
|
||||
## PAN-149915
|
||||
|
||||
Fixed an issue where a Panorama virtual appliance was unable to manage more than 2,500 firewalls when 28 or more CPU cores were available.
|
||||
|
||||
## PAN-149696
|
||||
|
||||
Fixed an intermittent issue where the GlobalProtect portal stopped responding with a 502 Bad Gateway response page when trying to access the portal URL using a web browser.
|
||||
|
||||
## PAN-149645
|
||||
|
||||
Fixed an issue in a virtual wire deployment configured with **Link State Pass Through** enabled where, when one member port went down, the peer port took longer than expected to change the status to **Down**.
|
||||
|
||||
## PAN-149547
|
||||
|
||||
Fixed an issue where, after a change in Security policies, traffic logs for inner GTP-U sessions did not show IMSI or IMEI fields following a commit.
|
||||
|
||||
## PAN-149377
|
||||
|
||||
A fix was made to address a vulnerability regarding information exposure through log files in PAN-OS that made it possible for configuration secrets for HTTP, email, and SNMP trap v3 log forwarding server profiles to be logged to the logrcvr.log system log ([CVE-2021-3032](https://security.paloaltonetworks.com/CVE-2021-3032)).
|
||||
|
||||
## PAN-149001
|
||||
|
||||
Fixed an issue where, when using certificate profiles configured under specific virtual systems (vsys), the GlobalProtect **Machine Certification Check** and **HIP Object** fail during a client certificate check.
|
||||
|
||||
## PAN-148818
|
||||
|
||||
Fixed an issue where the decryption profile was configured without the **Block sessions with expired certificates** option, but the firewall still blocked websites that were signed by an Expired AddTrust Root CA (certificate authority).
|
||||
|
||||
## PAN-148767
|
||||
|
||||
Fixed an issue where the firewall incorrectly created GTP-U sessions from Create Session Request and Create Session Response packets.
|
||||
|
||||
## PAN-148441
|
||||
|
||||
Fixed an issue where required processes were not automatically restarted on the Log Processing Card (LPC) or the Log Forwarding Card (LFC).
|
||||
|
||||
## PAN-147847
|
||||
|
||||
Fixed an issue where traffic didn't hit the intended Security policy if SSL forward proxy was enabled and service was set to **application-default**.
|
||||
|
||||
## PAN-147796
|
||||
|
||||
Fixed an issue on the firewalls with an IPsec/Encapuslating Security Payload (ESP) traffic with GlobalProtect gateway configuration where multiple processes (flow_ctrl, pktlog_forwarding, and all_task) restarted, which caused the device to reboot.
|
||||
|
||||
## PAN-147529
|
||||
|
||||
Fixed an issue where **ValidateAll** jobs were incorrectly logged as **CommitAll** in the configuration log of the firewall.
|
||||
|
||||
## PAN-147385
|
||||
|
||||
Fixed an issue where firewall buffers were depleted with GTP traffic due to the mishandling of conflicting sessions.
|
||||
|
||||
## PAN-147305
|
||||
|
||||
Fixed an issue where a process (useridd) stopped responding to requests.
|
||||
|
||||
## PAN-147298
|
||||
|
||||
```caveat
|
||||
PA-7050 and PA-7080 firewalls with 100G NPC only
|
||||
```
|
||||
|
||||
Fixed an issue where jumbo frames brought down the Network Processing Card (NPC) when traffic traversed the firewall at a high rate.
|
||||
|
||||
## PAN-147036
|
||||
|
||||
Fixed an issue where TCP connections got stuck between the firewall and the Log Collector if some packets were dropped on the path between the two appliances.
|
||||
|
||||
## PAN-146763
|
||||
|
||||
Fixed a configuration issue on a multi-vsys where the configured interface service route for email schedule reports was not being used.
|
||||
|
||||
## PAN-146215
|
||||
|
||||
```caveat
|
||||
FPP offload based hardware model only
|
||||
```
|
||||
|
||||
Fixed an issue where, when UDP traffic that was received on a tunnel had back-to-back client-to-server packets, random packets dropped.
|
||||
|
||||
## PAN-145996
|
||||
|
||||
An update was made to change the following system log message: DO NOT CHOOSE WMI in Active-Directory FOR YOUR USE CASE IF SEE THIS LOG AGAIN IN <number> SECONDS to Please change server monitor(log server) Transport Protocol from WMI to WinRM for better performance. This update also reduces the severity from **High** to **Informational**.
|
||||
|
||||
## PAN-144410
|
||||
|
||||
Debug logs were added to detect an out-of-memory (OOM) condition that caused the management server to restart.
|
||||
|
||||
## PAN-143090
|
||||
|
||||
Fixed an issue where the firewall silently dropped TCP out-of-order packets.
|
||||
|
||||
## PAN-142867
|
||||
|
||||
Fixed an issue where service session timeout override was not used for custom applications and the default value was chosen instead.
|
||||
|
||||
## PAN-142604
|
||||
|
||||
Fixed an issue where virtual memory of a process (configd) continuously increased until it stopped responding.
|
||||
|
||||
## PAN-142548
|
||||
|
||||
Fixed an memory leak issue in a process (configd) that caused the firewall to be inaccessible.
|
||||
|
||||
## PAN-140669
|
||||
|
||||
Fixed a memory leak issue caused by a process (mgmtsrvr).
|
||||
|
||||
## PAN-140492
|
||||
|
||||
Fixed an issue on the firewall where, with SSL Forward Proxy feature enabled, random file downloads over a decrypted session would stall or hang in the middle.
|
||||
|
||||
## PAN-139661
|
||||
|
||||
Fixed an issue that led to exhaustion of memory, which resulted in path monitoring failures when Cortex Data Lake was configured.
|
||||
|
||||
## PAN-139007
|
||||
|
||||
Fixed an issue where **URL Filtering** logs were misaligned when exported from the firewall due to the presence of a comma in the **User-Agent** field of the logs.
|
||||
|
||||
## PAN-138573
|
||||
|
||||
Fixed an issue where the keyword **[Disabled]** was missing from the disabled policies exported in CSV/PDF format.
|
||||
|
||||
## PAN-137741
|
||||
|
||||
Fixed an issue where the data for a botnet report was deleted before the botnet report was completed.
|
||||
|
||||
## PAN-137375
|
||||
|
||||
Fixed an issue where a process (ikmgr) stopped responding during IKE SA negotiations when Online Certificate Status Protocol (OCSP) was enabled.
|
||||
|
||||
## PAN-136652
|
||||
|
||||
```caveat
|
||||
PA-3200 Series and PA-800 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where you were unable to disable auto negotiation on small form-factor pluggable (SFP) ports.
|
||||
|
||||
## PAN-136607
|
||||
|
||||
Fixed an issue with GTP event packet capture (pcap) where enabling **Packet Capture** did not work.
|
||||
|
||||
## PAN-134909
|
||||
|
||||
Fixed an issue where region information was not called due to a mismatch in uppercase and lowercase letters in the region name.
|
||||
|
||||
## PAN-134840
|
||||
|
||||
Fixed an issue where pre-logon users failed authentication if the cookie was expired, instead of using certificate authentication.
|
||||
|
||||
## PAN-134467
|
||||
|
||||
Fixed an issue with the GlobalProtect portal where pre-logon authentication failed when agent Config Selection Critiera was configured on the firewall.
|
||||
|
||||
## PAN-134251
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where unplugging cables from Quad Small Form-factor Pluggable (QSFP) interfaces on 100G NPC causes path monitoring failures.
|
||||
|
||||
## PAN-133885
|
||||
|
||||
Fixed an issue where DNS proxy failed due to incorrect mapping of the DNS transaction ID.
|
||||
|
||||
## PAN-132055
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) was unresponsive when the number of active file descriptors was greater than 1024.
|
||||
|
||||
## PAN-129234
|
||||
|
||||
Fixed an issue where syslog connection failures were frequently reported in system logs.
|
||||
|
||||
## PAN-124681
|
||||
|
||||
A fix was made to address a vulnerability where Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5000 Series, PA-5200 Series, and PA-7000 Series firewalls were not cleared before the data frame was created ([CVE-2021-3031](https://security.paloaltonetworks.com/CVE-2021-3031)).
|
||||
|
||||
## PAN-121604
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where a process (brdagent) stopped responding during firewall bootup.
|
||||
|
||||
## PAN-110720
|
||||
|
||||
Fixed an issue where a high volume of traffic over SSL VPN caused a process (all_pktproc) to unexpectedly stop responding.
|
||||
|
||||
## PAN-109877
|
||||
|
||||
Fixed an issue where BGP flapped continuously with Jumbo Frames enabled on the firewall.
|
||||
|
||||
## PAN-100489
|
||||
|
||||
Fixed an issue where the **Group found** flag was set to **NO** on User-ID logs on the web interface, even when the user belonged to a group retrieved from the Active Directory (AD) server.
|
||||
@@ -0,0 +1,289 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.13
|
||||
---
|
||||
|
||||
## PAN-163538
|
||||
|
||||
Fixed an issue on multi-dataplane platforms where traffic through Large Scale VPN (LSVPN) tunnels dropped with the error message tunnel resolution failure.
|
||||
|
||||
## PAN-161121
|
||||
|
||||
Fixed an issue on the Panorama management server that caused invalid reference errors when attempting to delete an address object (**Objects > Addresses**) after removing the address object reference from an address group (**Objects > Address Groups**) resulting in you being unable to commit and push the configuration to managed firewalls.
|
||||
|
||||
## PAN-160376
|
||||
|
||||
Fixed an issue where, for local administrators using an authentication profile, the **save filter** (**Monitor > Logs**) option was grayed out.
|
||||
|
||||
## PAN-158650
|
||||
|
||||
Fixed an issue where several operations and processes stopped responding due to a deadlock issue between the CLI thread and the Terminal Server (TS) agent message processing the thread.
|
||||
|
||||
## PAN-158328
|
||||
|
||||
Fixed an issue where the firewall stopped populating the multicast FIB table with OIL entries for multicast groups.
|
||||
|
||||
## PAN-157049
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall processed internal path monitoring packets more slowly than expected when processing large amounts of traffic, which caused the dataplane to restart.
|
||||
|
||||
## PAN-156375
|
||||
|
||||
Fixed an issue where multiple all_pktoproc daemons restarted while processing HTTP/2 traffic in sw_offload.
|
||||
|
||||
## PAN-155656
|
||||
|
||||
Fixed an issue where multicast RTP traffic triggered unicast RTP Control Protocol (RTCP), and the predict session failed to install, which blocked the parent RTP session from forwarding packets.
|
||||
|
||||
## PAN-155517
|
||||
|
||||
Fixed an issue where a sudden increase in URL-cloud data challenged the cache capacity of the device.
|
||||
|
||||
## PAN-155453
|
||||
|
||||
Fixed an issue in the configuration logs where the destination zone was masked by asterisks.
|
||||
|
||||
## PAN-155294
|
||||
|
||||
Fixed an issue where iPad devices did not display Captive Portal multi-factor authentication (MFA) pages correctly when using Okta for push notifications.
|
||||
|
||||
## PAN-154844
|
||||
|
||||
Fixed an issue where commits and autocommits repeatedly failed due to an out-of-memory (OOM) condition that disrupted the processes pan_task and devsrvr.
|
||||
|
||||
## PAN-154812
|
||||
|
||||
Fixed a memory leak issue related to a process (configd) that was caused by log queries filtering by address.
|
||||
|
||||
## PAN-154195
|
||||
|
||||
Fixed an issue where the firewall dropped VoIP traffic over IPSec with counters flow_predict_convert_rtp_drop and flow_predict_convert_failed.
|
||||
|
||||
## PAN-153526
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls with 100G NPC (Network Processing Cards) only
|
||||
```
|
||||
|
||||
Fixed an issue where multicast groups were not set correctly, which caused ARP entries to display as incomplete and not update to correct values.
|
||||
|
||||
## PAN-153294
|
||||
|
||||
Fixed an issue on the firewall where a GlobalProtect username authenticated via Kerberos was unnecessarily normalized to SAMAccountName format.
|
||||
|
||||
## PAN-153261
|
||||
|
||||
Fixed an issue where not all fragmented packets were transmitted, which caused increased packet buffer usage.
|
||||
|
||||
## PAN-152998
|
||||
|
||||
Fixed an issue where the User-ID process CPU usage remained high when a large number of TS agents were configured but only a few were connected.
|
||||
|
||||
## PAN-152813
|
||||
|
||||
Fixed an issue with configuration memory leaks on Panorama that caused a process (configd) to restart.
|
||||
|
||||
## PAN-152743
|
||||
|
||||
Fixed an issue where, when initial flows from both directions reached the firewall at the same time, a race condition occurred, which caused the firewall to display the following error message: Duplicate flows detected while inserting <number>;, flow <number> with the same key. The flow keys were identical due to the flows having the same SRC and DST ports.
|
||||
|
||||
## PAN-152648
|
||||
|
||||
Fixed an issue where multiple all_pktproc processes stopped responding, which caused the dataplane to restart.
|
||||
|
||||
## PAN-152253
|
||||
|
||||
Fixed an issue where the Destination NAT with **DNS Rewrite** enabled and set to **forward** did not work when the destination IP address was a single IP address instead of an IP range.
|
||||
|
||||
## PAN-152103
|
||||
|
||||
Fixed a memory leak issue where a process (dnsproxy) did not properly release memory after use.
|
||||
|
||||
## PAN-152098
|
||||
|
||||
Fixed an issue where the Policy Optimizer for some device groups showed incorrect data with a - character in the rule usage column.
|
||||
|
||||
## PAN-151888
|
||||
|
||||
Fixed an issue where remote users were able to save log filters, which created a local user with the same username. With this fix, remote users cannot save a log filter.
|
||||
|
||||
## PAN-151503
|
||||
|
||||
Fixed an intermittent issue where memory was not fully freed after a Panorama commitAll completion on the firewall.
|
||||
|
||||
## PAN-151458
|
||||
|
||||
Fixed an issue on firewalls with high availability active/active configurations where GlobalProtect gateways timed out on-demand connections. This occurred because the **Inactivity Logout** timer did not reset.
|
||||
|
||||
## PAN-150998
|
||||
|
||||
Fixed an issue where, when deploying a VM-Series firewall on VMware NSX that had been assigned a serial number that was used by a previously deactivated firewall, the new firewall was deployed in a deactivated or partially deactivated state.
|
||||
|
||||
## PAN-150968
|
||||
|
||||
Fixed a rare issue with HTTP/2 decryption that caused packet header bytes to be corrupted, which caused packet drops.
|
||||
|
||||
## PAN-150867
|
||||
|
||||
An enhancement was made to enable additional logging during kernel panic/oops that helps identify the cause.
|
||||
|
||||
## PAN-150852
|
||||
|
||||
Fixed an issue with SMTP that occurred when attachment file names were longer than the allocated buffer. If the file name was longer than the buffer and Layer 7 inspection was enabled, the file was dropped, which caused session errors and an email to not be sent.
|
||||
|
||||
## PAN-150798
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where Network Processing Cards (NPC) took longer than expected or failed to boot.
|
||||
|
||||
## PAN-150085
|
||||
|
||||
Fixed an issue where a process (configd) stopped responding which caused context switches to slow.
|
||||
|
||||
## PAN-150008
|
||||
|
||||
Fixed an issue on the firewall where configuring auto-tagging based on URL filtering logs resulted in tags being added to source IP addresses and not matching the log forwarding filter match criteria.
|
||||
|
||||
## PAN-149641
|
||||
|
||||
Fixed an issue where firewalls stopped refreshing IP tag information when configured with the **VM Information Sources** feature with a VMWare vCenter Server.
|
||||
|
||||
## PAN-149339
|
||||
|
||||
Fixed an issue where, when an ECMP route changed, the flow table in the offload engine was not updated.
|
||||
|
||||
## PAN-149283
|
||||
|
||||
Fixed an issue where editing device log forwarding in the collector group then filtering specific firewalls and adding new firewalls caused the old firewalls to disappear from the log forwarding preferences list.
|
||||
|
||||
## PAN-148549
|
||||
|
||||
Fixed an issue where newly created interface management profiles were unable to be linked to subinterfaces.
|
||||
|
||||
## PAN-147959
|
||||
|
||||
Fixed an issue where the last commit state did not change to config sent to device when pushing a device group configuration in the **Managed Device > Summary** page on Panorama.
|
||||
|
||||
## PAN-147254
|
||||
|
||||
jQuery was updated to 3.5.1.
|
||||
|
||||
## PAN-147221
|
||||
|
||||
Improved QoS scheduling for Bidirectional Forwarding Detection (BFD) and BGP to address the internal handling of BGP and BFD packets under high resource constraints
|
||||
|
||||
## PAN-146787
|
||||
|
||||
Fixed an issue where traffic incorrectly matched URL based authentication policies.
|
||||
|
||||
## PAN-146236
|
||||
|
||||
Fixed an issue where the firewall was unable to properly create stream control transmission protocol (SCTP) sessions for multi-homed environments when multiple endpoints on the same SCTP associations sent INIT/INIT-ACK chunks during handshakes.
|
||||
|
||||
## PAN-145733
|
||||
|
||||
Fixed an issue where the SNMP INDEX for panZoneTable on the PAN-COMMON-MIB.my file did not work as expected, which led to entries in panZoneTable not being uniquely identified.
|
||||
|
||||
## PAN-145417
|
||||
|
||||
Debug commands were added to address an issue where the firewall connect to Cortex Data Lake due to the Online Certificate Status Protocol (OSCP) message missing the nextUpdate value in the OSCP response.
|
||||
|
||||
## PAN-144975
|
||||
|
||||
Fixed an intermittent issue where a high traffic load in a Layer 2 deployment caused SNMP and Panorama health monitoring failures.
|
||||
|
||||
## PAN-144887
|
||||
|
||||
```caveat
|
||||
Panorama virtual appliances in high availability (HA) configurations with VMware NSX plugin only
|
||||
```
|
||||
|
||||
Fixed an issue where dynamic address group updates and configuration pushes failed when new plugins were installed or uninstalled, or when a process (configd) was restarted or reinitialized.
|
||||
|
||||
## PAN-144538
|
||||
|
||||
Fixed an issue where locally disabling the rule hit-count feature on Panorama caused a memory leak.
|
||||
|
||||
## PAN-143485
|
||||
|
||||
Fixed a memory leak issue related to a process (devsrvr).
|
||||
|
||||
## PAN-143332
|
||||
|
||||
Fixed an issue where deploying the Master Key to managed devices through Panorama using the **Deploy Master Key** feature (**Panorama > Managed Devices > Summary > Deploy Master Key**) failed.
|
||||
|
||||
## PAN-141255
|
||||
|
||||
Removed the fields **device SN** and **device name** on Panorama from the predefined filter used in **Log Forwarding** and **Log Settings**.
|
||||
|
||||
## PAN-140222
|
||||
|
||||
Fixed an issue where logs were not forwarded to the syslog server with the following error message: profile: Syslog (1) is duplicated.
|
||||
|
||||
## PAN-137233
|
||||
|
||||
Fixed an issue where authenticating to GlobalProtect via expired SAML requests (waiting more than 10 minutes) still sent authentication to the SAML server. This invalidated the previously connected gateway and connected users to the second best gateway.
|
||||
|
||||
## PAN-136073
|
||||
|
||||
Fixed an issue where the High Speed Chassis Interconnect (HSCI) port flapped continuously after an upgrade or reboot.
|
||||
|
||||
## PAN-134799
|
||||
|
||||
Fixed an issue where packets of the same session were forwarded through a different member of an Aggregate Ethernet (AE) group once the session was offloaded.
|
||||
|
||||
## PAN-134461
|
||||
|
||||
Fixed an issue where an admin user authenticated to Panorama with RADIUS and assigned a Device Group and Template Admin role using access domains was unable to add a managed firewall to Panorama and received the following error message: Import failed user <username> does not exist.
|
||||
|
||||
## PAN-131474
|
||||
|
||||
A fix was made to address a vulnerability related to information exposure through log files in PAN-OS where the connection details for a scheduled configuration export were logged in system logs ([CVE-2021-3037](https://security.paloaltonetworks.com/CVE-2021-3037)).
|
||||
|
||||
## PAN-129927
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls with Layer 3 subinterfaces reset Class of Service (CoS) bits in 802.1q.
|
||||
|
||||
## PAN-126815
|
||||
|
||||
Fixed an issue where the GlobalProtect gateway and portal failed to generate authentication cookies for pre-logon and user-logon events due to a failure to populate the remote_addr field in the authentication cookie.
|
||||
|
||||
## PAN-124579
|
||||
|
||||
Fixed an issue where a process (all_task_3) restarted, which caused the tunnels to reset.
|
||||
|
||||
## PAN-123638
|
||||
|
||||
Fixed an issue where DHCP was not configurable from Panorama templates in single virtual system (vsys) mode.
|
||||
|
||||
## PAN-123041
|
||||
|
||||
Fixed an issue where commits failed due to OOM events caused by the PAN-DB database.
|
||||
|
||||
## PAN-120013
|
||||
|
||||
Fixed an issue where secure communication settings were incorrectly synchronized between Panorama appliances in an HA configuration.
|
||||
|
||||
## PAN-119161
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls were unable to start up an NPC due to a process (brdagent) restarting repeatedly.
|
||||
|
||||
## PAN-79640
|
||||
|
||||
Fixed an issue where the firewall intermittently logged incorrect actions for WildFire submissions and reports.
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.14-h4
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
Fixed a Denial-of-Service (DoS) vulnerability in the GlobalProtect portal and gateway ([CVE-2021-3063](https://security.paloaltonetworks.com/CVE-2021-3063)).
|
||||
|
||||
## PAN-171203
|
||||
|
||||
Fixed an issue in a high availability configuration where, when one firewall was active and its peer was in a suspended state, the suspended firewall continued to send traffic, which triggered the detection of duplicate MAC addresses.
|
||||
@@ -0,0 +1,336 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.14
|
||||
---
|
||||
|
||||
## WF500-5568
|
||||
|
||||
Fixed an issue where a firewall in FIPS mode running PAN-OS 8.1.18 or a later version failed to connect with a WildFire appliance in normal mode.
|
||||
|
||||
## WF500-5513
|
||||
|
||||
Fixed an issue where cloud queries failed, which generated system logs. The issue occurred because a hash was not found in the cloud.
|
||||
|
||||
## PAN-170740
|
||||
|
||||
Fixed an issue with the google-docs-uploading application that occurred if a Security policy rule was applied to a Security profile and traffic was decrypted.
|
||||
|
||||
## PAN-168921
|
||||
|
||||
Fixed an issue in active/active high availability (HA) configurations where traffic with complete packets was showing up as incomplete and being disconnected due to a non-session owner device closing the session prematurely.
|
||||
|
||||
## PAN-168298
|
||||
|
||||
Fixed an issue where a firewall superuser using an LDAP authentication profile that was pushed from Panorama was unable to save the filter under **Monitor > Logs**.
|
||||
|
||||
## PAN-167989
|
||||
|
||||
Fixed a timing issue between downloading and installing threads that occurred when Panorama pushed content updates and the firewall fetched content updates simultaneously.
|
||||
|
||||
## PAN-166836
|
||||
|
||||
Fixed an issue where session failed due to resource unavailability.
|
||||
|
||||
## PAN-166328
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls with NPCs only
|
||||
```
|
||||
|
||||
Fixed an issue where path monitoring failure occurred while hot inserting a 100G NPC (network processing card) into the firewall.
|
||||
|
||||
## PAN-166296
|
||||
|
||||
Fixed an issue where an unavailable certificate revocation list (CRL) from the server side caused an infinite loop on a process (sslmgr), which resulted in it not responding for other tasks.
|
||||
|
||||
## PAN-166241
|
||||
|
||||
A fix was made to address an improper restriction of XML external identity (XXE) reference in the PAN-OS web interface that enabled an authenticated administrator to read any arbitrary file from the file system and send a specifically crafted request to the firewall that caused the service to crash ([CVE-2021-3055](https://security.paloaltonetworks.com/CVE-2021-3055)).
|
||||
|
||||
## PAN-165661
|
||||
|
||||
Fixed an issue in an HA active/active configuration where an administrative shutdown message was not sent to the BGP peer when the firewall went into a suspended state, which delayed convergence.
|
||||
|
||||
## PAN-164922
|
||||
|
||||
Fixed an issue on Panorama where a context switch to a managed firewall running PAN-OS 8.1.0 to PAN-OS 8.1.19 failed.
|
||||
|
||||
To utilize this fix, upgrade Panorama to PAN-OS 10.0.5.
|
||||
|
||||
## PAN-164846
|
||||
|
||||
Fixed an issue where packet buffers were depleted.
|
||||
|
||||
## PAN-164646
|
||||
|
||||
Fixed an issue where tunnel monitoring in the Large Scale VPN (LSVPN) displayed as down in both the CLI and the web interface due to incorrect dataplane ownership.
|
||||
|
||||
## PAN-164422
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
A fix was made to address improper access control that enabled an attacker with authenticated access to GlobalProtect portals and GlobalProtect gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon Web Services (AWS) ([CVE-2021-3062](https://security.paloaltonetworks.com/CVE-2021-3062)).
|
||||
|
||||
## PAN-164056
|
||||
|
||||
Fixed a memory issue for LSVPNs with multiple dataplane systems.
|
||||
|
||||
## PAN-162710
|
||||
|
||||
Debug code was introduced to enable additional logging for flow lookup.
|
||||
|
||||
## PAN-162600
|
||||
|
||||
Fixed an issue where, when the GlobalProtect client sent UDP/4501 traffic that was destined for the GlobalProtect gateway inside the GlobalProtect tunnel, the firewall still processed the traffic, which caused routing loops.
|
||||
|
||||
## PAN-161260
|
||||
|
||||
Fixed a memory leak issue related to a process (useridd) that occurred when processing high amount of HIP reports as well as a memory leak issue related to the sslvpn process that occurred when the firewall was configured as a GlobalProtect satellite.
|
||||
|
||||
## PAN-160744
|
||||
|
||||
Fixed an issue where the negative time difference between the dataplane and the management plane during the client certificate info check prevented the GlobalProtect client from connecting to the GlobalProtect gateway with the following error message: Required client certificate not found.
|
||||
|
||||
## PAN-160455
|
||||
|
||||
A fix was made to address an issue where certain invalid URL entries contained in an External Dynamic List (EDL) caused the devsrvr process to stop responding ([CVE-2021-3048](https://security.paloaltonetworks.com/CVE-2021-3048)).
|
||||
|
||||
## PAN-159944
|
||||
|
||||
Fixed an issue where a process (dnsproxyd) stopped responding due to an error in the DNS cache operation.
|
||||
|
||||
## PAN-159826
|
||||
|
||||
Fixed an issue where SSL VPN memory leaked when the default browser for SAML authentication on GlobalProtect was not enabled.
|
||||
|
||||
## PAN-159295
|
||||
|
||||
Fixed an issue where scheduled configuration export files saved in the /tmp folder in root were not periodically purged, which caused the root partition to fill up.
|
||||
|
||||
## PAN-159135
|
||||
|
||||
Fixed an issue where the firewall rejected SAML Assertions, which caused user authentication failure when the **Validate Identity Provider Certificate** was enabled in the SAML Server Profile in vsys3 or above.
|
||||
|
||||
## PAN-158988
|
||||
|
||||
Fixed an issue with HTTP Header Insertion where the payload was truncated when processing a segmented TCP stream and when the client retransmitted the packet with the same sequence number that was previously received segmented.
|
||||
|
||||
## PAN-158844
|
||||
|
||||
Adds additional debugging to be used in identifying the malformed references causing process crashes during FQDN refresh.
|
||||
|
||||
## PAN-158774
|
||||
|
||||
Fixed an issue where random DNS queries dropped with the counter ctd_dns_wait_pkt_drop when DNS security was enabled.
|
||||
|
||||
## PAN-158723
|
||||
|
||||
A fix was made to address an improper handling of exception conditions in the PAN-OS dataplane that enabled an unauthenticated network-based attacker to send specifically crafted traffic through the firewall that caused the service to crash ([CVE-2021-3053](https://security.paloaltonetworks.com/CVE-2021-3053)).
|
||||
|
||||
## PAN-158638
|
||||
|
||||
Fixed an issue where the firewall returned the following error message when attempting to request a device certificate using a one-time password (OTP): invalid ocsp response sig-alg.
|
||||
|
||||
## PAN-158439
|
||||
|
||||
Fixed a memory leak on the management server process on Firewall.
|
||||
|
||||
## PAN-158262
|
||||
|
||||
A buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS software allows remote attackers to execute arbitrary code.
|
||||
|
||||
A fix was made to address a buffer overflow vulnerability in the Telnet-based administrative management service included with PAN-OS that allowed a remote attacker to execute arbitrary code ([CVE-2020-10188](https://security.paloaltonetworks.com/CVE-2020-10188)).
|
||||
|
||||
## PAN-157834
|
||||
|
||||
Fixed an issue with missing zone entries in CSV or PDF export files.
|
||||
|
||||
## PAN-157721
|
||||
|
||||
Fixed an issue where the firewall dropped GPRS tunneling protocol (GTPv2) Create Session Requests and Responses that had IEs 201 and 202 with the error Abnormal GTPv2-C message with invalid IE.
|
||||
|
||||
## PAN-157346
|
||||
|
||||
Fixed an issue where HIP custom checks for plist failed when the HIP exclusion category were configured under (**Mobile User Template > Network > GlobalProtect > Portal<portal-config> > Agent<agent-config> > HIP Data Collection**).
|
||||
|
||||
## PAN-157035
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where multicast packets traversing the firewall in VLAN configurations experienced higher drop rates than expected.
|
||||
|
||||
## PAN-157027
|
||||
|
||||
Fixed an issue where, when stateless GTP-U traffic hit a multi-dataplane firewall, an inter-dataplane fragmentation loop occurred, which caused high dataplane resource usage.
|
||||
|
||||
## PAN-156482
|
||||
|
||||
Fixed a packet buffer issue where HTTP2 packets were held for category lookup and the HTTP request was across multiple packets.
|
||||
|
||||
## PAN-156240
|
||||
|
||||
A fix was made to address an issue where a cryptographically weak pseudo-random number (PRNG) was used during authentication to the PAN-OS interface. As a result, attackers with the capability to observe their own authentication secrets over a long duration on the firewall had the ability to impersonate another authenticated web interface administrator’s session ([CVE-2021-3047](https://security.paloaltonetworks.com/CVE-2021-3047)).
|
||||
|
||||
## PAN-156225
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the HA1-B port remained down after an upgrade from PAN-OS 9.1.4 to later 9.1 releases and from PAN-OS 10.0.0 to PAN-OS 10.0.4.
|
||||
|
||||
## PAN-155049
|
||||
|
||||
Fixed an issue with SSLVPN memory leaks related to the GlobalProtect portal **Config Selection Criteria**.
|
||||
|
||||
## PAN-154602
|
||||
|
||||
Fixed an issue where GlobalProtect users got disconnected after modifying floating IP HA configuration.
|
||||
|
||||
## PAN-154557
|
||||
|
||||
Fixed an issue that caused a process (useridd) core dump when parsing the Subject Alternative Name from a client certificate sent in the HIP report.
|
||||
|
||||
## PAN-154403
|
||||
|
||||
Fixed an issue with HIP matching logic for missing patches where previous behavior indicated missing patches when no patches were missing.
|
||||
|
||||
## PAN-154376
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
|
||||
|
||||
## PAN-154016
|
||||
|
||||
Fixed an issue where auto-commits failed for VM-Series firewalls bootstrapped with new content installation during bootstrap. The firewalls displayed the following error message: Details:Error: Undefined application <application-name>.
|
||||
|
||||
## PAN-153814
|
||||
|
||||
Fixed an issue where the firewall displayed the URL Filtering Safe Search Block Page on the specific site only, even when the traffic was matched to a specific rule that did not have any URL filtering policies.
|
||||
|
||||
## PAN-153382
|
||||
|
||||
Fixed an issue where the per-minute resource monitor was three minutes behind.
|
||||
|
||||
## PAN-153316
|
||||
|
||||
CLI commands were added to address an issue where virtual memory on a process (configd) exceeded the new 32G limit.
|
||||
|
||||
- To disable the virtual memory limit, use debug software disable-virt-limit.
|
||||
- To enable the virtual memory limit, use debug software enable-virt-limit.
|
||||
|
||||
## PAN-153213
|
||||
|
||||
Fixed a rare issue where TCP packets randomly dropped due to reassembly failure.
|
||||
|
||||
## PAN-152497
|
||||
|
||||
Fixed an issue where the firewall was unable to create a new GTP-U session when it received Create Session Response messages, which caused the following error message to display in the GTP log: GTPv1 message failed stateful inspection.
|
||||
|
||||
## PAN-152458
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls on Microsoft Hyper-V only
|
||||
```
|
||||
|
||||
Fixed an issue where, when upgrading to PAN-OS 9.0.8 or later, ethernet packets dropped after adding VLAN tags during egress from a subinterface. To leverage this fix, set the interface level maximum transmission unit (MTU) to 1496 or less.
|
||||
|
||||
## PAN-151521
|
||||
|
||||
Fixed an issue where a process (logrcvr) continuously restarted at pan_hash_iter_next_i.
|
||||
|
||||
## PAN-151395
|
||||
|
||||
Fixed an issue where the firewall repeatedly logged connection failures to a configured Log Collector.
|
||||
|
||||
## PAN-150534
|
||||
|
||||
Fixed an issue where authentication logs with the subtype SAML were not forwarded to the syslog server.
|
||||
|
||||
## PAN-150467
|
||||
|
||||
Fixed a memory leak issue with a unified query that caused a process (mprelay) to restart due to an out-of-memory (OOM) condition.
|
||||
|
||||
## PAN-150337
|
||||
|
||||
A fix was made to address a reflect cross-site scripting (XSS) vulnerability in the PAN-OS web interface that enabled an authenticated network-based attacker to mislead another authenticated PAN-OS administrator to click on a specially crafted link that performed arbitrary actions in the web interface as the targeted authenticated administrator ([CVE-2021-3052](https://security.paloaltonetworks.com/CVE-2021-3052)).
|
||||
|
||||
## PAN-150110
|
||||
|
||||
Fixed an issue where Elasticsearch restarted unexpectedly when it ran out of memory. This was due to the vm.max-map-count value being set incorrectly in the newer version of Elasticsearch (starting from PAN-OS 9.0). With this fix, the value is set correctly.
|
||||
|
||||
## PAN-150023
|
||||
|
||||
A fix was made to address an issue where an improper authentication vulnerability enabled a Security Assertion Markup Language (SAML) authenticated user to impersonate any user in the GlobalProtect portal and GlobalProtect gateway when they were configured to use SAML authentication ([CVE-2021-3046](https://security.paloaltonetworks.com/CVE-2021-3046)).
|
||||
|
||||
## PAN-149501
|
||||
|
||||
A fix was made to address a memory corruption vulnerability in the GlobalProtect Clientless VPN that enabled an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication ([CVE-2021-3056](https://security.paloaltonetworks.com/CVE-2021-3056)).
|
||||
|
||||
## PAN-147827
|
||||
|
||||
Fixed an issue where, when SIP traffic traversing the firewall was sent with a high QoS Differentiated Services Code Point (DSCP) value, the DSCP value was reset to the default setting (CS0).
|
||||
|
||||
## PAN-147783
|
||||
|
||||
Checks were added to help prevent the dataplane from restarting.
|
||||
|
||||
## PAN-147781
|
||||
|
||||
A fix was made to address an issue where an OS command argument injection vulnerability in the PAN-OS web interface enabled an authenticated administrator to read any arbitrary file from the file system ([CVE-2021-3045](https://security.paloaltonetworks.com/CVE-2021-3045)).
|
||||
|
||||
## PAN-146250
|
||||
|
||||
Fixed an issue where, in two separate but simultaneous sessions, the same software packet buffer was owned and processed.
|
||||
|
||||
## PAN-146107
|
||||
|
||||
Fixed an issue where memory allocation failure caused a process (pan_comm) to restart several times, which caused the firewall to restart.
|
||||
|
||||
## PAN-144470
|
||||
|
||||
Fixed an issue where driver descriptor rings were out of sync in the control plane to dataplane direction, which caused internal path monitoring heartbeat failures.
|
||||
|
||||
## PAN-142621
|
||||
|
||||
Fixed an issue where the firewall was unable to log debug information in case of kernel panic.
|
||||
|
||||
## PAN-141813
|
||||
|
||||
Fixed an issue where multiple daemons restarted due to a management plane ARP overflow.
|
||||
|
||||
## PAN-138727
|
||||
|
||||
A fix was made to address a time-of-check to time-of-use (TOCTOU) race condition in the PAN-OS web interface that enabled an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges ([CVE-2021-3054](https://security.paloaltonetworks.com/CVE-2021-3054)).
|
||||
|
||||
## PAN-137147
|
||||
|
||||
Fixed an issue where configuration commits failed due to the dataplane running out of memory in policy cache allocation.
|
||||
|
||||
## PAN-136347
|
||||
|
||||
Fixed an issue where DNS proxy TCP connections were processed incorrectly, which caused a process (dnsproxy) to stop responding.
|
||||
|
||||
## PAN-133886
|
||||
|
||||
Fixed an issue where GlobalProtect users were unable to connect to mobile gateways when download of a large CRL failed due to timeouts that resulted in CRL check failures.
|
||||
|
||||
## PAN-132035
|
||||
|
||||
Fixed an issue on Panorama appliances in an active/passive HA configuration where a managed firewall generated high priority alerts that it failed to connect to the passive Panorama appliance's User-ID agent server. This issue occurred because the firewall was only able to connect to one Panorama User-ID server at a time, and it connected only to the active Panorama appliance's User-ID server.
|
||||
|
||||
## PAN-115553
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where internal path monitoring failed, which caused the firewall to unexpectedly restart.
|
||||
|
||||
## PAN-110429
|
||||
|
||||
Fixed an issue with firewalls in an HA configuration where multiple all_pktproc processes stopped responding due to missing heartbeats, which caused service outages.
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.16-h2
|
||||
---
|
||||
|
||||
## PAN-190175
|
||||
|
||||
A fix was made to address an OpenSSL infinite loop vulnerability in the PAN-OS software ([CVE-2022-0778](https://security.paloaltonetworks.com/CVE-2022-0778)).
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.16-h3
|
||||
---
|
||||
|
||||
## PAN-192999
|
||||
|
||||
A fix was made to address [CVE-2022-0028](https://security.paloaltonetworks.com/CVE-2022-0028).
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.16-h6
|
||||
---
|
||||
|
||||
## PAN-237871
|
||||
|
||||
```caveat
|
||||
WF-500 appliances and PAN-DB private cloud deployments only
|
||||
```
|
||||
|
||||
Fixed an issue where the root-cert was set to expire on December 31, 2023. With this fix, the expiration date has been extended.
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.16-h7
|
||||
---
|
||||
|
||||
## PAN-237876
|
||||
|
||||
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||
|
||||
## PAN-215576
|
||||
|
||||
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||
@@ -0,0 +1,17 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.17-h1
|
||||
---
|
||||
|
||||
## PAN-159364
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-152022
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
|
||||
## PAN-136676
|
||||
|
||||
A fix was made to address customer and internal bugs.
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.17-h5
|
||||
---
|
||||
|
||||
## PAN-239241
|
||||
|
||||
Extended the root certificate for WildFire appliances to December 31, 2032.
|
||||
|
||||
## PAN-237935
|
||||
|
||||
Extended the offline PAN-DB, Panorama, and WildFire certificates which were previously set to expire on September 2, 2024.
|
||||
|
||||
## PAN-237876
|
||||
|
||||
Extended the firewall Panorama root CA certificate which was previously set to expire on April 7th, 2024.
|
||||
|
||||
## PAN-215576
|
||||
|
||||
Fixed an issue where the userID-Agent and TS-Agent certificates were set to expire on November 18, 2024. With this fix, the expiration date has been extended to January 2032.
|
||||
@@ -0,0 +1,37 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.17
|
||||
---
|
||||
|
||||
## PAN-189414
|
||||
|
||||
Fixed an issue where TCP packets were dropped during the first zone transfer when DNS security was enabled.
|
||||
|
||||
## PAN-188303
|
||||
|
||||
Fixed an issue where the serial number displayed as unknown after running the show system state CLI command.
|
||||
|
||||
## PAN-180916
|
||||
|
||||
Fixed an issue where DNS security caused the (time-to-live) value of the pointer record (PTR) to be overwritten with a value of 30 seconds.
|
||||
|
||||
## PAN-176153
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls with 20G NPC (Network Processing Cards) only
|
||||
```
|
||||
|
||||
Fixed a memory allocation issue where the NPC was unable to successfully boot up on the firewall.
|
||||
|
||||
## PAN-175003
|
||||
|
||||
Fixed a connection issue with the sysd process that caused FIB entries to not be updated.
|
||||
|
||||
## PAN-149008
|
||||
|
||||
Fixed an issue where the CLI command Show config running following the CLI command set cli op-command-xml-output on produces an unreadable output.
|
||||
|
||||
## PAN-127479
|
||||
|
||||
A fix was made to address [CVE-2022-0022](https://security.paloaltonetworks.com/CVE-2022-0022).
|
||||
@@ -0,0 +1,177 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.1
|
||||
---
|
||||
|
||||
## PAN-113911
|
||||
|
||||
Fixed an issue on PA-5200 Series firewalls where the dataplane stopped responding due to a deadlock when you accessed the stream session table.
|
||||
|
||||
## PAN-113845
|
||||
|
||||
Fixed an issue where content installation failed and displayed the following error message: Error: failed to handle TDB_UPDATE_BLOCK, after you upgraded to PAN-OS® 9.0.
|
||||
|
||||
## PAN-113771
|
||||
|
||||
A security-related fix was made to allow Online Certificate Status Protocol (OCSP) checks while disallowing HTTP calls.
|
||||
|
||||
## PAN-113682
|
||||
|
||||
Fixed an issue where the dataplane restarted when processing HTTP/2 traffic with padded DATA frames.
|
||||
|
||||
## PAN-113675
|
||||
|
||||
A security-related fix was made to address an authentication bypass vulnerability in PAN-OS Management Web Interface (CVE-2019-1572/PAN-SA-2019-0005).
|
||||
|
||||
## PAN-113512
|
||||
|
||||
Fixed an issue where an XML API response for an external dynamic list did not return invalid or ignored members after you upgraded to PAN-OS 9.0.
|
||||
|
||||
## PAN-113446
|
||||
|
||||
Fixed an issue where the firewall unintentionally generated the following system log: Installed content package WildFire is newer than available package, skipping, when you checked for WildFire® updates.
|
||||
|
||||
## PAN-113302
|
||||
|
||||
Fixed an issue where commits to the Panorama™ configuration after you upgraded to PAN-OS 9.0 failed with the following error message: statistics-service is invalid.
|
||||
|
||||
## PAN-112700
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls in an HA configuration only
|
||||
```
|
||||
|
||||
Fixed an issue that occurred after you upgraded to PAN-OS 9.0 where some logs displayed a different rule name than the rule name associated with the universally unique identifier (UUID).
|
||||
|
||||
## PAN-112592
|
||||
|
||||
Fixed an issue on a firewall where the system log did not generate an alert for AutoFocus™ license expiry.
|
||||
|
||||
## PAN-112458
|
||||
|
||||
Fixed an issue on a firewall where the management server stopped responding when debugs were configured and you exported traffic logs (**Monitor** > **Traffic <traffic-name>** > **Export to CSV**).
|
||||
|
||||
## PAN-112428
|
||||
|
||||
Fixed an intermittent issue where autocommits failed and Panorama stopped displaying device groups when managing a WildFire appliance that was running an earlier maintenance release of the same feature release (such as using Panorama running PAN-OS 8.1.6 to manage a WF-500 appliance that was running PAN-OS 8.1.3).
|
||||
|
||||
## PAN-112305
|
||||
|
||||
Fixed an issue where source (**Object** > **Dynamic Lists <list-name>** > **Create List**) URLs, which contained double escape characters caused external dynamic list entries to display incorrect values in the policies.
|
||||
|
||||
## PAN-112274
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where a process (configd) stopped responding when a role-based user with privacy settings disabled, viewed a scheduled report that required data anonymization.
|
||||
|
||||
## PAN-112098
|
||||
|
||||
Fixed an intermittent issue on a firewall where outbound traffic failed with an error message: (proxy decrypt failure) when configured with HTTP Header Insertion (**Objects** > **Security Profiles** > **URL Filtering <filter-name>** > **HTTP Header Insertion**).
|
||||
|
||||
## PAN-111897
|
||||
|
||||
Fixed an issue where the tags were not set on OSPFv3 routes redistributed to BGP-3.
|
||||
|
||||
## PAN-111850
|
||||
|
||||
Fixed an issue where the firewall did not capture the number of packets in the threat packet capture (pcap) as configured in the extended packet capture length setting.
|
||||
|
||||
## PAN-111822
|
||||
|
||||
```caveat
|
||||
PA-3200, PA-5200, and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue on a firewall configured with policy-based forwarding (PBF) and symmetric return, where traffic dropped because the ARP table did not get updated.
|
||||
|
||||
## PAN-111638
|
||||
|
||||
Fixed an issue where the external dynamic list did not update after a scheduled refresh of the list.
|
||||
|
||||
## PAN-111061
|
||||
|
||||
A fix was made to upgrade OpenSSH software included with PAN-OS ([PAN-SA-2020-0005](https://security.paloaltonetworks.com/PAN-SA-2020-0005) / CVE-2016-10012).
|
||||
|
||||
## PAN-111052
|
||||
|
||||
Fixed an issue where a firewall silently dropped TCP packets when you enabled the Antivirus profile while the software deterministic finite automation (DFA) option is disabled (DFA is disabled by default).
|
||||
|
||||
## PAN-110441
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewall only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where the internal path monitoring failed, which caused the firewall to unexpectedly restart.
|
||||
|
||||
## PAN-110341
|
||||
|
||||
Fixed an issue where the firewall sent RIP updates more frequently than expected.
|
||||
|
||||
## PAN-110336
|
||||
|
||||
```caveat
|
||||
PA-3000, PA-3200, PA-5000, PA-5200, and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where a process (mpreplay) restarted and caused the offload traffic to drop.
|
||||
|
||||
## PAN-108620
|
||||
|
||||
Fixed an issue where Traps ESM logs were sent to the Log Collector but did not display in the web interface (**Monitor** > **Traps ESM**).
|
||||
|
||||
## PAN-108575
|
||||
|
||||
Fixed an issue where a process (configd) stopped responding and displayed the following error message: configd is down.
|
||||
|
||||
## PAN-108409
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where scheduled dynamic updates pushed from Panorama to the managed firewalls failed.
|
||||
|
||||
## PAN-108113
|
||||
|
||||
Fixed an issue where Bidirectional Forwarding Detection (BFD) did not function on a static route for which the next hop for that route was an FQDN (instead of an IP address).
|
||||
|
||||
## PAN-108111
|
||||
|
||||
Fixed an issue where Bidirectional Forwarding Detection (BFD) did not function on a BGP peer that was identified using an FQDN (instead of an IP address).
|
||||
|
||||
## PAN-107677
|
||||
|
||||
Fixed an issue on GlobalProtect™ where Security Assertion Markup Language (SAML) authentication failed when you used a macOS operating system.
|
||||
|
||||
## PAN-107006
|
||||
|
||||
Fixed an issue where you were unable to search for service objects by destination port numbers.
|
||||
|
||||
## PAN-106963
|
||||
|
||||
Fixed an issue where the firewall did not display the full URL information in the URL Filtering log (**Monitor** > **URL Filtering**) after a ( '\r' ) return character.
|
||||
|
||||
## PAN-106249
|
||||
|
||||
```caveat
|
||||
PA-200, PA-220, and PA-800 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the Block IP List option, which is not supported, displayed in the administrator role profile (**Device** > **Admin Role** > **Web UI**).
|
||||
|
||||
## PAN-104263
|
||||
|
||||
Fixed an issue where the RTC battery reading exceeded the maximum threshold value.
|
||||
|
||||
## PAN-103023
|
||||
|
||||
Fixed an intermittent issue where a job type (content) caused a firewall configuration failure and the firewall to stop responding.
|
||||
|
||||
## PAN-96827
|
||||
|
||||
Fixed an issue where BGP command output formats did not display consistently across different PAN-OS releases.
|
||||
|
||||
## PAN-92155
|
||||
|
||||
Fixed an issue where administrators were unable to configure an IP address using templates for HA2 (**Device** > **High Availability** > **Data Link (HA2)**) after setting the configuration to **IP** or **Ethernet** for Panorama management servers in HA configuration.
|
||||
|
||||
## PAN-85691
|
||||
|
||||
Fixed an issue where Authentication policy rules that were based on multi-factor authentication (MFA) didn't block connections to an MFA vendor when the MFA server profile specified a Certificate Profile that had the wrong certificate authority (CA) certificate.
|
||||
@@ -0,0 +1,191 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.2
|
||||
---
|
||||
|
||||
## WF500-5023
|
||||
|
||||
Fixed an issue on WF-500 appliances where the cluster service took longer than expected to start due to a large number of queued sample data.
|
||||
|
||||
## WF500-5022
|
||||
|
||||
Fixed an issue where a non-functioning CLI command was removed from WF-500 appliances.
|
||||
|
||||
## WF500-4974
|
||||
|
||||
Fixed an issue on a WF-500 appliance where the static analysis results displayed in the PDF report but did not display in the WildFire® analysis summary of the web interface.
|
||||
|
||||
## WF500-4844
|
||||
|
||||
Fixed an issue on WildFire appliance clusters where the passive-controller responded with the incorrect Common Name (CN) in the certificate, which caused the registration to fail.
|
||||
|
||||
## WF500-4838
|
||||
|
||||
Fixed an intermittent issue on a WF-500 appliance where WildFire reports took longer than expected to generate, which caused the task to automatically timeout.
|
||||
|
||||
## WF500-4784
|
||||
|
||||
Fixed an issue on a WF-500 appliance where during a reboot, the following error message displayed: FATAL: module nbd not found.
|
||||
|
||||
## WF500-4743
|
||||
|
||||
Fixed an intermittent issue on a WF-500 appliance where the CLI command debug wildfire reset global-database fix became unresponsive.
|
||||
|
||||
## PAN-118065
|
||||
|
||||
```caveat
|
||||
M-Series Panorama™ management servers in Management Only mode
|
||||
```
|
||||
|
||||
When you delete the local Log Collector (**Panorama** > **Managed Collectors**), it disables the 1/1 ethernet interface in the Panorama configuration as expected but the interface still displays as Up when you execute the show interface all command in the CLI after you commit.
|
||||
|
||||
**Workaround:**Disable the 1/1 ethernet interface before you delete the local log collector and then commit the configuration change.
|
||||
|
||||
## PAN-116919
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall dropped packets passing through IPSec tunnels if you enabled jumbo frames (**Device** > **Setup** > **Session** > **Session Settings**).
|
||||
|
||||
## PAN-116658
|
||||
|
||||
Fixed a rare issue where the firewall sent HTTP/2 DATA frames with incorrect padding byte lengths, which caused software buffer corruption and a process (all_pktproc) to stop responding.
|
||||
|
||||
## PAN-116316
|
||||
|
||||
Fixed an issue where RTP and RTCP predict sessions failed, which caused the firewall to stop processing RTSP-based video streaming.
|
||||
|
||||
## PAN-116084
|
||||
|
||||
Fixed an issue where a VM-Series firewall on Microsoft Azure deployed using MMAP dropped traffic when the firewall was experiencing heavy traffic.
|
||||
|
||||
## PAN-115592
|
||||
|
||||
Fixed an issue where the firewall rebooted due to a plugin memory leak.
|
||||
|
||||
## PAN-115591
|
||||
|
||||
Fixed an issue where the snmpd process was leaking memory when polling for global counters.
|
||||
|
||||
## PAN-114984
|
||||
|
||||
Fixed OpenSSL vulnerability CVE-2019-1559, see [PAN-SA-2019-0039](https://securityadvisories.paloaltonetworks.com/Home/Detail/202) for details.
|
||||
|
||||
## PAN-114893
|
||||
|
||||
Fixed an issue where a context switch from Panorama to a firewall did not respond as expected when a web browser was used.
|
||||
|
||||
## PAN-114804
|
||||
|
||||
Fixed an issue where a configuration change resets to "default" when you conducted a search in the Categories (**Objects** > **URL Filtering** > **Categories**) web interface.
|
||||
|
||||
## PAN-114601
|
||||
|
||||
Fixed an issue where the Allow List (**Device** > **Setup** > **Authentication Setting** > **<authentication profile - name>** > **Authentication**) did not update after you added new users to a group in the Active Directory.
|
||||
|
||||
## PAN-114255
|
||||
|
||||
Fixed an issue where Bidirectional Forwarding Detection (BFD) went down temporarily during a commit or EDL refresh if you configured a large value for the BFD Hold Time.
|
||||
|
||||
## PAN-114003
|
||||
|
||||
Fixed an issue on a Panorama management server running PAN-OS 9.0 where a context switch to firewalls did not respond.
|
||||
|
||||
## PAN-113829
|
||||
|
||||
Fixed an issue where, after you upgraded the firewall to PAN-OS® 9.0, a firewall configured from "none" to "allow" in the custom URL category reverted to "none" after a commit.
|
||||
|
||||
## PAN-113692
|
||||
|
||||
Fixed an intermittent issue on a firewall in a high availability (HA) active/passive configuration where five minutes after a failover test IP routes disappeared, which caused traffic interruptions.
|
||||
|
||||
## PAN-113608
|
||||
|
||||
Fixed an issue on a firewall with packet capture (pcap) enabled where the log receiver stopped responding when larger than expected packets were received.
|
||||
|
||||
## PAN-113414
|
||||
|
||||
Fixed an issue where the User-ID™ (useridd) process stopped responding.
|
||||
|
||||
## PAN-112815
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where a process (useridd) did not respond to the alternate user attribute (**Device** > **User Identification** > **Group Mapping Settings** > **<group mapping-name>** > **User and Group Attributes**) on the passive firewall during a restart.
|
||||
|
||||
## PAN-112814
|
||||
|
||||
Fixed an issue where H.323-based calls lost audio because the predicted H.245 session was not converted to Active status, which caused the firewall to drop the H.245 traffic.
|
||||
|
||||
## PAN-112729
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where Decrypted Sessions Info (**Panorama** > **Managed Devices** > **Health** > **All Devices** > **<device-name>** > **Sessions**) did not display as expected for VM-Series firewalls.
|
||||
|
||||
## PAN-112699
|
||||
|
||||
```caveat
|
||||
VM-Series firewall on AWS running on a C5 or M5 instance only
|
||||
```
|
||||
|
||||
Fixed an issue where you were unable use the mgmt-interface-swap command to [swap the interfaces](https://docs.paloaltonetworks.com/vm-series/9-0/vm-series-deployment/set-up-the-vm-series-firewall-on-aws/about-the-vm-series-firewall-on-aws/management-interface-mapping-for-use-with-amazon-elb.html) for deploying a VM-Series firewall behind a web load balancer (such as AWS ALB or Classic ELB).
|
||||
|
||||
## PAN-112626
|
||||
|
||||
Fixed an issue where a new DNS Security subscription was not available on your VM-Series firewall after you upgraded to a PAN-OS 9.0® release with a PAYG Bundle 2 license.
|
||||
|
||||
## PAN-112445
|
||||
|
||||
Fixed an issue on a firewall in an HA active/passive configuration where a race condition caused the firewall to stop responding after an HA1 link flap.
|
||||
|
||||
## PAN-112340
|
||||
|
||||
Fixed an issue with performance, including high CPU usage, that occurred when you enabled URL Filtering without enabling Threat Prevention in an environment that processes a large number (thousands) of URL look-ups per second per dataplane.
|
||||
|
||||
## PAN-112194
|
||||
|
||||
Fixed an issue where packet buffers did not release GlobalProtect™ clientless VPN packets, which caused the firewall to stop responding.
|
||||
|
||||
## PAN-111679
|
||||
|
||||
Fixed an issue where URL filtering profiles were being incorrectly applied to security policies during a commit.
|
||||
|
||||
## PAN-111553
|
||||
|
||||
Fixed an issue on the Panorama management server where the **Include Device and Network Templates** setting (**Commit** > **Push to Devices** > **Edit Selections** or **Commit** > **Commit and Push** > **Edit Selections**) was disabled by default and caused your push attempts to fail. With this fix, your push will **Include Device and Network Templates** by default.
|
||||
|
||||
## PAN-111540
|
||||
|
||||
Fixed an issue on PA-5200 Series firewalls where the dataplane stopped responding when the session table was full.
|
||||
|
||||
## PAN-111251
|
||||
|
||||
Fixed an issue where administrators were unable to use the CLI to enable or disable DNS Rewrite under a Destination NAT policy rule (they were able to execute the command but the firewall did not implement the change).
|
||||
|
||||
## PAN-110390
|
||||
|
||||
Fixed an issue on PA-7000 Series firewalls where invalid filters caused the device management server to stop responding when you generated a database (DB) report from a remote firewall.
|
||||
|
||||
## PAN-110273
|
||||
|
||||
Fixed an issue where you were unable to establish OSPF neighborship when an OSPF routing protocol was configured with MD5 authentication and one of the firewalls was restarted.
|
||||
|
||||
## PAN-109672
|
||||
|
||||
Fixed an issue on a VM-Series firewall in an HA active/passive configuration where the passive firewall received buffered packets while in an idle state when the data plane development kit (DPDK) is enabled.
|
||||
|
||||
## PAN-109344
|
||||
|
||||
Fixed an issue where service objects did not import into Panorama when you configured them identically but with different names.
|
||||
|
||||
## PAN-108374
|
||||
|
||||
Fixed an issue on GlobalProtect where you were unable to authenticate when the domain name included the ampersand ( "&" ) character.
|
||||
|
||||
## PAN-106518
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where predefined DHCP options did not accept template variables when you configured a DHCP server for a template.
|
||||
|
||||
## PAN-101341
|
||||
|
||||
Fixed an issue where administrators configured with Device Group and Template Admin type were unable to perform a global search and returned the following message: Unauthorized request.
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.3-h2
|
||||
---
|
||||
|
||||
## PAN-120745
|
||||
|
||||
An enhancement was made to the IP Options field in the TCP/IP header for zone protection profiles.
|
||||
@@ -0,0 +1,505 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.4
|
||||
---
|
||||
|
||||
## BLANK-000000
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
Updates to support changes in Azure Accelerated Networking (AN).
|
||||
|
||||
## WF500-4785
|
||||
|
||||
Fixed a rare issue on WF-500 appliances where the firewall did not respond after you upgraded the appliance from a PAN-OS® 8.0.1 release to a PAN-OS 8.0.10 or later release. With this fix, you can run the new debug software raid fixup auto CLI command to recover the RAID controller.
|
||||
|
||||
## PAN-124658
|
||||
|
||||
Fixed an issue where the timer system call activated more frequently than expected, which caused higher than expected CPU usage.
|
||||
|
||||
## PAN-123371
|
||||
|
||||
Fixed an issue where the Wildfire® Analysis Report incorrectly displayed the following error message: You are not authorized to access this page on the web interface.
|
||||
|
||||
## PAN-123079
|
||||
|
||||
Fixed an intermittent issue where after a configuration change, a commit caused the dataplane to stop responding.
|
||||
|
||||
## PAN-122804
|
||||
|
||||
Fixed an issue on Panorama™ M-Series and virtual appliances where the firewall stopped forwarding logs to Cortex™ Data Lake after you upgraded the cloud services plugin to 1.4.
|
||||
|
||||
## PAN-122489
|
||||
|
||||
```caveat
|
||||
Microsoft Azure only
|
||||
```
|
||||
|
||||
Fixed an issue where VM-Series firewalls incorrectly renamed (to eth) interfaces connected to Mellanox appliances when **Accelerated networking** was enabled on the firewall.
|
||||
|
||||
## PAN-122004
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did not respond when plugged in with a Finisar 100G AOC cable.
|
||||
|
||||
## PAN-121449
|
||||
|
||||
Fixed an issue where **Remove Config** (**Panorama** > **Plugins**) did not remove the configuration for any plugins you have set up on Panorama.
|
||||
|
||||
## PAN-121185
|
||||
|
||||
Fixed an intermittent issue where domains were not normalized, which caused an incorrect verdict response.
|
||||
|
||||
## PAN-120662
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls using PA-7000-20G-NPC cards only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where an out-of-memory (OOM) condition caused the dataplane or internal path monitoring to stop responding.
|
||||
|
||||
## PAN-120548
|
||||
|
||||
Fixed an issue where the Captive Portal request limit was ignored when you configured the Captive Portal authentication method to browser-challenge.
|
||||
|
||||
## PAN-120409
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls running a 20G Network Processing Card (NPC) or a 20GQ NPC dropped stream control transmission protocol (SCTP) connections due to incorrect session handling.
|
||||
|
||||
## PAN-120342
|
||||
|
||||
Fixed an intermittent issue where the dataplane stopped responding when processing a UDP packet that passed through an IPSec tunnel.
|
||||
|
||||
## PAN-120194
|
||||
|
||||
```caveat
|
||||
Virtual and M-Series Panorama appliances and Log Collectors only
|
||||
```
|
||||
|
||||
Fixed an issue where closed Elasticsearch (ES) indices were continuing to receive and re-queue logs, which resulted in high CPU usage.
|
||||
|
||||
## PAN-119257
|
||||
|
||||
Fixed an issue where the firewall could not establish an IKEv2 connection with SHA256 certificates.
|
||||
|
||||
## PAN-119187
|
||||
|
||||
```caveat
|
||||
Panorama only
|
||||
```
|
||||
|
||||
Fixed an issue where a file lock was released before the lock was taken, which triggered an erroneous maximum connection timeout that prevented administrators from logging in to and executing commands from the command-line interface (CLI).
|
||||
|
||||
## PAN-119030
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where bootstrapped managed firewalls were disconnected after you performed a partial revert if you did not first perform a manual commit. With this fix, the manual commit is not required.
|
||||
|
||||
## PAN-118964
|
||||
|
||||
Fixed an issue on VM-Series firewalls where single root I/O virtualization (SR-IOV) did not support packet mmap in access mode and DPDK mode.
|
||||
|
||||
## PAN-118784
|
||||
|
||||
Fixed an intermittent issue where the firewall dropped a message: Update PDP Context Response and did not update the General Packet Radio Service (GPRS) Tunneling Protocol for User Data (GTP-U).
|
||||
|
||||
## PAN-118509
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where shared policies were out of sync due to an empty stream control transmission protocol (SCTP) after you upgraded the firewall from PAN-OS 8.0.16 to PAN-OS 8.1.8.
|
||||
|
||||
## PAN-118423
|
||||
|
||||
Fixed an intermittent issue with local high availability (HA) status changes where a process (mprelay) failed to commit changes to the HA state.
|
||||
|
||||
## PAN-118411
|
||||
|
||||
Fixed an issue where ARP entries took longer than expected to age out in a single run.
|
||||
|
||||
## PAN-118407
|
||||
|
||||
Fixed an issue where an internal path monitoring failure due to a buffer leak caused the firewall to reboot.
|
||||
|
||||
## PAN-117923
|
||||
|
||||
Fixed an issue where the management server stopped responding when an incorrect filter was used to filter traffic logs instead of displaying an error message.
|
||||
|
||||
## PAN-117921
|
||||
|
||||
Fixed an issue where you were unable to create GTP inner sessions, which caused the firewall to drop GTP-U data packets when the firewall was deployed on S1-U and S-11 interfaces.
|
||||
|
||||
## PAN-117916
|
||||
|
||||
Fixed an issue where the dataplane stopped responding when you pushed permitted IP addresses from Panorama to managed firewalls.
|
||||
|
||||
## PAN-117720
|
||||
|
||||
```caveat
|
||||
GlobalProtect™ Clientless VPN environments only
|
||||
```
|
||||
|
||||
Fixed an issue where a process (all_pktproc) stopped responding and caused the firewall to restart unexpectedly when processing GlobalProtect Clientless VPN traffic. To leverage this fix, you must first upgrade (**Devices** > **Dynamic Updates**) to GlobalProtect Clientless VPN content release 79 or a later release.
|
||||
|
||||
## PAN-116807
|
||||
|
||||
```caveat
|
||||
PA-7000, PA-5200, and PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall dropped ICMP error messages when the security policy was configured to allow ICMP.
|
||||
|
||||
## PAN-116798
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where the progress bar for a commit all job incorrectly remained at 0% after a job was completed.
|
||||
|
||||
## PAN-116769
|
||||
|
||||
Fixed an issue where a process (pan_comm) stopped responding due to a memory allocation error.
|
||||
|
||||
## PAN-116729
|
||||
|
||||
Fixed an issue where you were unable to deploy bootstrapped content in offline environments due to content validity checks.
|
||||
|
||||
## PAN-116634
|
||||
|
||||
Fixed an issue where the date in the GlobalProtect HTTP header was incorrectly set to a random date instead of a zero (0), which negatively and falsely impacted security scorecard ratings.
|
||||
|
||||
## PAN-116613
|
||||
|
||||
Fixed an issue on a VM-Series firewall deployed in Microsoft Azure where packets dropped silently due to a kernel error.
|
||||
|
||||
## PAN-116513
|
||||
|
||||
Fixed an issue where VM-Series firewalls did not bootstrap successfully when you included the software version in the software folder of the bootstrap package.
|
||||
|
||||
## PAN-116436
|
||||
|
||||
```caveat
|
||||
Panorama virtual appliances only
|
||||
```
|
||||
|
||||
Fixed an issue where a disk calculation error resulted in an erroneous opt/panlogs/ partion full condition and caused a process (CDB) to stop responding.
|
||||
|
||||
## PAN-116416
|
||||
|
||||
Fixed an issue on Panaorama M-Series and virtual appliances where a process (configd) stopped responding when you performed a commit to a large number of firewalls.
|
||||
|
||||
## PAN-116383
|
||||
|
||||
Fixed an issue with Panorama on Azure where the configuration of an HA pair became out of sync due to different plugin versions being detected even though the same versions were installed on both peers.
|
||||
|
||||
## PAN-116280
|
||||
|
||||
Fixed an issue where the firewall displayed a static route warning when the next hop IP address was not included in the subnet of the outgoing interface.
|
||||
|
||||
## PAN-116227
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where traffic logs did not display data when the IPv6 address filter is based on netmask.
|
||||
|
||||
## PAN-116218
|
||||
|
||||
Fixed an issue where the test routing bgp virtual-router default restart peer Peer-v6 CLI command did not execute the operational request and returned the following error message: op command for client routed timed out as client is not available.
|
||||
|
||||
## PAN-116128
|
||||
|
||||
Fixed an issue where a process (logrcvr) stopped responding when packet captures (pcap) were generated for HTTP2 traffic.
|
||||
|
||||
## PAN-116123
|
||||
|
||||
Fixed an issue where a process (devsrvr) stopped responding when you performed a commit or a configuration validation when the proxy ID contained 24 or more characters.
|
||||
|
||||
## PAN-115856
|
||||
|
||||
Fixed an issue where Dynamic IP and Port (DIPP) NAT pools did not release used ports after all sessions were removed.
|
||||
|
||||
## PAN-115852
|
||||
|
||||
Fixed an issue on VM-Series firewalls on AWS where you could not change maximum transmission unit (MTU) values from the web interface and displayed the following error message: Malformed Request.
|
||||
|
||||
## PAN-115794
|
||||
|
||||
Fixed an issue where, after you upgraded the firewall from PAN-OS 8.1.5 to PAN-OS 9.0.0, the firewall displayed the following validation error: plugins 'read-only' is not an allowed keyword.
|
||||
|
||||
## PAN-115792
|
||||
|
||||
Fixed an issue where after a refresh of the external dynamic list values from the previous list were not retained, which caused the list values to display 0.0.0.0 and displayed the following error message: HTTP/1.1 500 Internal Server Error.
|
||||
|
||||
## PAN-115748
|
||||
|
||||
Fixed an intermittent issue on Panorama M-Series and virtual appliances where a memory issue caused the firewall to reboot.
|
||||
|
||||
## PAN-115738
|
||||
|
||||
Fixed an issue where data logs were generated but the firewall did not forward the logs to the syslog server.
|
||||
|
||||
## PAN-115695
|
||||
|
||||
Fixed an intermittent issue where a large number of packets were received before acknowledgments were complete, which depleted descriptor queue entries and resulted in high latency during data transfers even though CPU usage looked normal.
|
||||
|
||||
## PAN-115450
|
||||
|
||||
Fixed a rare issue where a race condition occurred between daemons during a tunnel re-key, which caused BGP sessions to drop from Large Scale VPN tunnels. To leverage this fix, you must run the debug rasmgr delay-nh-update CLI command.
|
||||
|
||||
## PAN-115354
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where renaming a device group followed by a partial commit did not change the device group hierarchy as expected.
|
||||
|
||||
## PAN-115287
|
||||
|
||||
Fixed an issue where commits failed and displayed the following error message: Commit job was not queued. All daemons are not available.
|
||||
|
||||
## PAN-115219
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where Global Find caused the web interface to stop responding when you searched for common English words.
|
||||
|
||||
## PAN-115186
|
||||
|
||||
Fixed an issue where SaaS reports were not generated due to report definitions not getting pushed to the log collector.
|
||||
|
||||
## PAN-114958
|
||||
|
||||
Fixed an issue where the User-ID™ (useridd) process consumed more CPU cycles than expected when you configured User-ID redistribution.
|
||||
|
||||
## PAN-114889
|
||||
|
||||
Fixed an issue where a Panorama template push to a firewall with a PAN-OS 8.1 release or earlier resulted in the deletion of split tunnel configurations when any address objects or address groups are included. With this fix, you still must remove all address groups before pushing templates to a PAN-OS 8.1 or earlier release.
|
||||
|
||||
## PAN-114867
|
||||
|
||||
Fixed an issue where GlobalProtect gateway client configuration generation failed when a matching rule existed.
|
||||
|
||||
## PAN-114844
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where malformed API calls caused the firewall to reboot.
|
||||
|
||||
## PAN-114779
|
||||
|
||||
Fixed an issue where log purging took longer than expected, which prevented the firewall from capturing traffic logs.
|
||||
|
||||
## PAN-114567
|
||||
|
||||
Fixed an issue where the Eventid eq globalprotectportal-config-succ system query caused the management server (mgmtsrvr) process to stop responding.
|
||||
|
||||
## PAN-114566
|
||||
|
||||
Fixed an issue where after a commit the firewall displayed the following error message: No Valid DNS Security License even when the license was valid and successfully applied.
|
||||
|
||||
## PAN-114533
|
||||
|
||||
Fixed an issue where traffic was blocked by the safe search enforcement instead of the intended allow rule.
|
||||
|
||||
## PAN-114526
|
||||
|
||||
Fixed an issue where larger than expected number of packets sent over a GTP-U tunnel caused packet captures to fill the files faster than expected. With this fix, you can run the debug dataplane packet-diag set capture gtpu-lvl [1-30] command to ensure GTP-U traffic are captured.
|
||||
|
||||
## PAN-114475
|
||||
|
||||
Fixed an issue where Panorama in FIPS mode defaulted to FIPS-CC mode instead of Normal mode.
|
||||
|
||||
## PAN-114427
|
||||
|
||||
Fixed an issue where an empty host name in the HTTP header caused a web server process (websrvr) to stop responding when you accessed the captive portal redirect page.
|
||||
|
||||
## PAN-114264
|
||||
|
||||
Fixed an issue where sessions were offloaded as the application identification was performed when you configured a custom application with **Continue scanning for other application**.
|
||||
|
||||
## PAN-114160
|
||||
|
||||
Fixed an issue where you were unable to download ZIP files greater than 3GB through a GlobalProtect Clientless VPN application.
|
||||
|
||||
## PAN-114105
|
||||
|
||||
Fixed an issue on a Panorama M-Series appliance where the Summary (**Panorama** > **Managed Devices** > **Summary**) web interface refreshes every 10 seconds when set to manually refresh.
|
||||
|
||||
## PAN-114090
|
||||
|
||||
Fixed an issue on a Panorama virtual appliance in Legacy mode and in an HA active/passive configuration where logs were forwarded only to the active firewall.
|
||||
|
||||
## PAN-114002
|
||||
|
||||
Fixed an issue where you were unable to import variable CSV files when variable names contained a character space.
|
||||
|
||||
## PAN-113971
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the High Speed Chassis Interconnect (HSCI) link flapped after you rebooted the firewall.
|
||||
|
||||
## PAN-113930
|
||||
|
||||
Fixed an issue on VM-Series firewalls where CPU loads were uneven across cores when more than 8 cores were allocated to the dataplane.
|
||||
|
||||
## PAN-113912
|
||||
|
||||
Fixed an issue where a process (ikemgr) stopped responding and caused the firewall to reboot.
|
||||
|
||||
## PAN-113887
|
||||
|
||||
Fixed an issue where loading custom app tags did not complete successfully, which prevented subsequent requests (such as commits, content installs, and FQDN refreshes) from executing as expected.
|
||||
|
||||
## PAN-113870
|
||||
|
||||
Fixed an issue where Security policies were not evaluated in sequential order when the policy was based on URL categories.
|
||||
|
||||
## PAN-113796
|
||||
|
||||
Fixed an issue where GlobalProtect configured with the **pre-logon then on-demand** connect method was unable to authenticate during **pre-logon** when you configured the portal and gateway with an Authentication Override and without a certification profile.
|
||||
|
||||
## PAN-113767
|
||||
|
||||
Fixed an issue where the firewall silently dropped packets when security profiles were attached and FPGA enabled AHO and DFA.
|
||||
|
||||
## PAN-113619
|
||||
|
||||
Fixed an issue where the GlobalProtect gateway did not assign an IP address when the local IP address was a supernet of the GlobalProtect pool.
|
||||
|
||||
## PAN-113501
|
||||
|
||||
Fixed an issue where the Panorama management server returned a Security Copy (SCP) server connection error after you created an SCP Scheduled Config Export profile (**Panorama** > **Scheduled Config Export**) due to the SCP server password exceeding 15 characters in length.
|
||||
|
||||
## PAN-113229
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances in an HA active/passive configuration where the passive firewall displayed an out-of-sync shared policy status when you edited the Device Group.
|
||||
|
||||
## PAN-113185
|
||||
|
||||
Fixed an issue where the passive firewall in an HA active/passive configuration was processing traffic.
|
||||
|
||||
## PAN-112988
|
||||
|
||||
Fixed an issue where a process (useridd) leaked memory, which caused the firewall to drop traffic and display the following error message: Out-of-memory condition detected, kill process.
|
||||
|
||||
## PAN-112972
|
||||
|
||||
Fixed an issue where scheduled reports were not generated as expected when you added groups in a query builder.
|
||||
|
||||
## PAN-112566
|
||||
|
||||
Fixed an issue where the GlobalProtect Client was unable to download files from a web interface, sessions went into DISCARD state, and displayed the following message: Packet dropped, control plane service not allowed.
|
||||
|
||||
## PAN-112529
|
||||
|
||||
Fixed an issue where the firewall incorrectly sent several benign critical content alerts daily.
|
||||
|
||||
## PAN-112467
|
||||
|
||||
Fixed an issue where obsolete IPv6 Neighbor Discovery (ND) entries did not clear as expected, which caused the IPv6 table to reach full capacity and caused new IPv6 ND entries to fail.
|
||||
|
||||
## PAN-112308
|
||||
|
||||
Fixed an issue where hardware security module (HSM) accounts were locked out after three attempts when you ran the show hsm ha-status CLI command.
|
||||
|
||||
## PAN-112016
|
||||
|
||||
Fixed an issue on VM-Series firewalls where the physical port counters on the dataplane interfaces did not increase on KVM when you disabled DPDK.
|
||||
|
||||
## PAN-111698
|
||||
|
||||
Fixed an issue where administrators were unable to log in when character spaces were used in usernames.
|
||||
|
||||
## PAN-111660
|
||||
|
||||
Fixed an issue where an incorrect SSH key initialization caused a process (pan_comm) to stop responding every 15 minutes when you configured an SSH proxy on the firewall.
|
||||
|
||||
## PAN-110990
|
||||
|
||||
Fixed an issue where a logical operation not configured with receive_time in the traffic log filter did not respond as expected.
|
||||
|
||||
## PAN-110960
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where commits failed when you configured an address group object in the Include List (**Network** > **Zone** > **<zone-name>** > **Include List**).
|
||||
|
||||
## PAN-110839
|
||||
|
||||
Fixed a rare issue where a commit pushed from Panorama failed, which caused a process (routed) to stop responding.
|
||||
|
||||
## PAN-110628
|
||||
|
||||
Fixed an issue where user groups were deleted from the Group Include List ("**Device** > **User identification** > **Group Mapping Settings** > **<group-name>** > **Group Include List**) if you changed the LDAP server profile account password.
|
||||
|
||||
## PAN-110234
|
||||
|
||||
Fixed an issue where administrators with a Superuser (read-only) role was able to initiate a commit through the CLI.
|
||||
|
||||
## PAN-110168
|
||||
|
||||
Fixed an issue where the firewall and Panorama web interface did not present HSTS headers to your web browser.
|
||||
|
||||
## PAN-109803
|
||||
|
||||
Fixed an issue where credential phishing prevention did not detect user or password phishing when passwords, which contained two discontiguous character spaces were used.
|
||||
|
||||
## PAN-109759
|
||||
|
||||
Fixed an issue where the firewall did not generate a notification for the GlobalProtect client when the firewall denied unencrypted TLS sessions due to an authentication policy match.
|
||||
|
||||
## PAN-107207
|
||||
|
||||
Fixed an issue where the VPN tunnel operational status incorrectly displays up even though the VPN tunnel is down.
|
||||
|
||||
## PAN-106889
|
||||
|
||||
Fixed a rare issue on a firewall in an HA active/passive configuration running in FIPS-CC mode where the passive firewall rebooted in to maintenance mode.
|
||||
|
||||
## PAN-106628
|
||||
|
||||
Fixed an issue where the firewall did not generate a system log when the firewall detected a RAM issue.
|
||||
|
||||
## PAN-106449
|
||||
|
||||
Fixed an issue when you connected to an internal GlobalProtect gateway on a firewall in an HA active/passive configuration and authenticated with multi-factor authentication (MFA) to access a resource, the first and second authentication factors succeeded but you would not be redirected to the actual resource.
|
||||
|
||||
## PAN-106100
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue on a firewall in an HA active/active configuration where SSL traffic through the GlobalProtect VPN (in SSL mode) tunnel stopped responding after Layer 7 processing completed and when asymmetric routing occurred.
|
||||
|
||||
## PAN-105286
|
||||
|
||||
Fixed an issue where the firewall did not record email header information in Data Filtering logs when you triggered a test mail that contained a data leak prevention (DLP) pattern.
|
||||
|
||||
## PAN-104909
|
||||
|
||||
Fixed an issue where the firewall incorrectly forwarded traffic when you configured the ingress interface with a QoS policy and the egress interface as a tunnel.
|
||||
|
||||
## PAN-104808
|
||||
|
||||
Fixed an issue where scheduled SaaS reports generated and emailed empty PDF reports.
|
||||
|
||||
## PAN-104251
|
||||
|
||||
Fixed an issue where the syslog server TCP keep-alive parameter caused the connection to unexpectedly age out.
|
||||
|
||||
## PAN-103865
|
||||
|
||||
Fixed an issue where the firewall did not detect user credentials when the number of users exceeded 60,000.
|
||||
|
||||
## PAN-103847
|
||||
|
||||
Fixed a memory buffer allocation issue that caused the Session Initiation Protocol (SIP) traffic NAT to stop responding.
|
||||
|
||||
## PAN-101613
|
||||
|
||||
```caveat
|
||||
PA-800 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where a congestion condition occurred during periods of low traffic. With this fix, run the set system setting hol-system enable CLI command to enable the HOL system mode.
|
||||
|
||||
## PAN-84670
|
||||
|
||||
Fixed an issue where firewalls that were not configured to decrypt HTTPS services and applications traffic allowed users without valid authentication timestamps to access those resources regardless of Authentication Policy settings. To prevent such access, either configure the firewall to decrypt traffic or run the debug device-server cp-allow-encrypted-disable on command and execute a commit force CLI command (this command will persist across reboots).
|
||||
@@ -0,0 +1,21 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.5-h3
|
||||
---
|
||||
|
||||
## PAN-134242
|
||||
|
||||
```caveat
|
||||
PA-7000 Series (PA-7000b with SMC-B) firewalls with Log Forwarding Cards (LFC) only
|
||||
```
|
||||
|
||||
Fixed an issue related to incorrect restrictions on communications to the LFC.
|
||||
|
||||
## PAN-114784
|
||||
|
||||
Fixed an issue where a process (devsrvr) stopped responding after you pushed a configuration from Panorama™ to a firewall.
|
||||
|
||||
## PAN-111333
|
||||
|
||||
An enhancement was made to increase the pattern match limit to recognize applications and threats accurately.
|
||||
@@ -0,0 +1,661 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.6
|
||||
---
|
||||
|
||||
## WF500-5343
|
||||
|
||||
Fixed an issue on WF-500 that caused cloud queries to fail when the cloud verdict did not match the local verdict.
|
||||
|
||||
## PAN-135141
|
||||
|
||||
Fixed an issue where the Log Processing Card (LPC) did not come up intermittently in a fully loaded PA-7000 Series.
|
||||
|
||||
## PAN-134242
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls with Log Forwarding Cards (LFC) only
|
||||
```
|
||||
|
||||
A security fix was made to restrict improper communications to the LFC (CVE-2019-17440/PAN-SA-2019-0040).
|
||||
|
||||
## PAN-133883
|
||||
|
||||
Fixed an issue where a race condition caused pan_task and pan_com to exit unexpectedly.
|
||||
|
||||
## PAN-133491
|
||||
|
||||
Fixed an issue where Internet Protocol (IP) to user mappings were not synced from the HUB virtual system (vsys) to the non-hub vsys.
|
||||
|
||||
## PAN-133448
|
||||
|
||||
Fixed an issue where the mprelay process could crash during commit if the devsrvr process was restarted before or during the commit.
|
||||
|
||||
## PAN-133443
|
||||
|
||||
Fixed an issue where an XML API call incorrectly masked the response, which prevented role based administrators from running the response.
|
||||
|
||||
## PAN-132501
|
||||
|
||||
Fixed an issue where after you switched the **Context** from Panorama™ to a firewall, the DESTINATION ZONE (**Policies > Security > <policy-name> > Destination**) incorrectly displayed none.
|
||||
|
||||
## PAN-132104
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where the <show><object><registered-ip></registered-ip></object></show> XML API call did not retrieve more than 500 entries.
|
||||
|
||||
## PAN-131939
|
||||
|
||||
Fixed an issue where DP crashed during file transfer due to one or more content updates being installed.
|
||||
|
||||
## PAN-130640
|
||||
|
||||
Fixed an issue where the management plane CPU on the firewall was high due to index generation on summary logs.
|
||||
|
||||
## PAN-130465
|
||||
|
||||
Fixed an issue where required fields were masked incorrectly in a XML API call, which hid the response.
|
||||
|
||||
## PAN-130073
|
||||
|
||||
Fixed an issue where a large number (65,000) of GlobalProtect™ user connections caused a process (sslvpn) to stop responding after you upgraded from PAN-OS® 8.1.10 to PAN-OS 8.1.11.
|
||||
|
||||
## PAN-130069
|
||||
|
||||
Fixed an issue where the firewall incorrectly interpreted an external dynamic list MineMeld instability error code as an empty external dynamic list.
|
||||
|
||||
## PAN-129668
|
||||
|
||||
Fixed an issue on the firewalls where the dataplane restarted unexpectedly when processing HTTP/2 traffic if packet-diag debugs were enabled.
|
||||
|
||||
## PAN-129658
|
||||
|
||||
Fixed an issue where GTP inspection stopped functioning after unrelated changes in policy and a commit followed by a high availability (HA) failover.
|
||||
|
||||
## PAN-129441
|
||||
|
||||
Fixed an issue where the concurrent file limitation for WildFire® submissions didn't work when the firewall had many files waiting to be uploaded, which caused /opt/panlogs/wildfire/tmpfile to become full and destabilize the firewall (for example, the process crashed or system logs were not written).
|
||||
|
||||
## PAN-129327
|
||||
|
||||
Fixed a rare timing window that caused an Internal packet path monitoring failure.
|
||||
|
||||
## PAN-129127
|
||||
|
||||
Fixed an issue where log export from maintenance mode failed with the following error message: no ip address configured, can't export logs even though the management interface Internet Protocol (IP) address was configured.
|
||||
|
||||
## PAN-128856
|
||||
|
||||
Fixed an issue where the disk usage calculation was getting corrupted and purging logs.
|
||||
|
||||
## PAN-128269
|
||||
|
||||
```caveat
|
||||
PA-5250, PA-5260, and PA-5280 firewalls with 100GB AOC cables only
|
||||
```
|
||||
|
||||
Fixed an issue where after you upgraded the first peer in a high availability (HA) configuration to a PAN-OS 9.0 release, the High Speed Chassis Interconnect (HSCI) port did not come up due to an FEC mismatch until after you finished upgrading the second peer.
|
||||
|
||||
## PAN-128248
|
||||
|
||||
A fix was made to address a vulnerability with a race condition due to an insecure creation of a file in a temporary directory in PAN-OS ([CVE-2020-2016](https://security.paloaltonetworks.com/CVE-2020-2016)).
|
||||
|
||||
## PAN-127649
|
||||
|
||||
Fixed an issue where a purge script stopped responding, which caused a process (logrcvr) to discard incoming logs.
|
||||
|
||||
## PAN-127089
|
||||
|
||||
Fixed an intermittent issue where the default route did not redistribute to an OSPF Not-So-Stubby Area (NSSA).
|
||||
|
||||
## PAN-126882
|
||||
|
||||
A security fix was made to address an OpenSSL vulnerability (CVE-2019-1547/CVE-2019-1563).
|
||||
|
||||
## PAN-126627
|
||||
|
||||
Fixed an issue where a process (all_pktproc) stopped responding due to a NULL pointer exception while cleaning up SSL proxy sessions previously configured for GlobalProtect.
|
||||
|
||||
## PAN-126283
|
||||
|
||||
Fixed an intermittent issue where after you configured **Cache EDNS Responses** (**Network > DNS Proxy > <DNS Proxy-name> > Advanced**) a process (dnsproxy) stopped responding.
|
||||
|
||||
## PAN-126159
|
||||
|
||||
Fixed an issue where the firewall did not match the Security policy when you configured the match condition to a shared local group.
|
||||
|
||||
## PAN-125996
|
||||
|
||||
Fixed an issue on Panorama M-Series and VM-Series where the configd process would crash.
|
||||
|
||||
## PAN-125898
|
||||
|
||||
Fixed an issue where a process (openssl) caused higher than expected management CPU usage due to the incompletion of the Online Certificate Status Protocol (OCSP) during the logging service certificate validation.
|
||||
|
||||
## PAN-125793
|
||||
|
||||
Fixed an issue where multiple No valid URL filtering license warning messages were generated during a commit due to an expired URL filtering license. With this fix, the warning messages are grouped into a single message per virtual system (vsys).
|
||||
|
||||
## PAN-125594
|
||||
|
||||
Fixed an issue where the configd process on a Panorama appliance had a memory leak during commit operations.
|
||||
|
||||
## PAN-125302
|
||||
|
||||
Fixed an issue where the real-time clock (RTC) battery voltage exceeded the maximum threshold and triggered alerts in the system log.
|
||||
|
||||
## PAN-125157
|
||||
|
||||
Fixed an issue on the firewalls where the rasmgr process restarted unexpectedly when using third-party VPN clients to connect to GlobalProtect.
|
||||
|
||||
## PAN-125122
|
||||
|
||||
A fix was made to address a cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS and Panorama that disclosed an authenticated PAN-OS administrator's PAN-OS session cookie ([CVE-2020-2013](https://security.paloaltonetworks.com/CVE-2020-2013)).
|
||||
|
||||
## PAN-125018
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where after you configure the firewall with an API call commits took longer than expected.
|
||||
|
||||
## PAN-125017
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where logs were unexpectedly discarded.
|
||||
|
||||
## PAN-124948
|
||||
|
||||
Fixed an issue where a null point (policy) dereference was causing a crash.
|
||||
|
||||
## PAN-124882
|
||||
|
||||
Fixed an issue where traffic logs that contained incorrect Security policies were generated during an active commit process when the Security policies were being added or removed.
|
||||
|
||||
## PAN-124858
|
||||
|
||||
Fixed an issue on PA-220, PA-820, and PA-850 firewalls where Custom Signatures caused the CTD memory depletion (OOM), which led to a dataplane crash.
|
||||
|
||||
## PAN-124781
|
||||
|
||||
Fixed an issue in Panorama where the **Policies > Security** web interface flashes and the selected security rule did not stay selected when making a change to a rule that was part of device group that included more than 200 rules.
|
||||
|
||||
## PAN-124593
|
||||
|
||||
A fix was made to address a missing XML validation vulnerability in the PAN-OS web interface ([CVE-2020-1975](https://security.paloaltonetworks.com/CVE-2020-1975)).
|
||||
|
||||
## PAN-124565
|
||||
|
||||
Fixed an issue where an out of memory condition caused commits to fail with the following error: Error unserializing profile objects failed to handle CONFIG_UPDATE_START.
|
||||
|
||||
## PAN-124435
|
||||
|
||||
Fixed an issue where the firewall dropped pre-VLAN spanning tree (PVST+) packets from the virtual wire interface when you executed the set session rewrite-pvst-pvid yes CLI command.
|
||||
|
||||
## PAN-124428
|
||||
|
||||
Fixed an issue where Address Resolution Protocol (ARP) randomly failed on one of the interfaces for a firewall deployed in the KVM/GCP/ESXi clouds.
|
||||
|
||||
## PAN-123857
|
||||
|
||||
Fixed an issue where HTTP/2 traffic inspection caused a software buffer leak over time and affected decryption traffic.
|
||||
|
||||
## PAN-123843
|
||||
|
||||
Fixed an issue for Cloud/VM platforms where the tunnels between the log collectors did not come up when a public IP was used for the log collectors in an environment with a Panorama management server and two or more log collectors.
|
||||
|
||||
## PAN-123747
|
||||
|
||||
Fixed an issue where App-ID™ signatures failed to match when there were more than 12 partial App-ID matches within the same session.
|
||||
|
||||
## PAN-123667
|
||||
|
||||
Fixed an issue where the snmpd process was crashing when polling for global counters.
|
||||
|
||||
## PAN-123661
|
||||
|
||||
A fix was made to address an authentication bypass vulnerability in the Panorama context switching feature ([CVE-2020-2018](https://security.paloaltonetworks.com/CVE-2020-2018)).
|
||||
|
||||
## PAN-123322
|
||||
|
||||
```caveat
|
||||
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls running PAN-OS 9.0.5 only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where a process (all_pktproc) stopped responding due to a Work Query Entry (WQE) corruption that was caused by duplicate child sessions.
|
||||
|
||||
## PAN-123306
|
||||
|
||||
Fixed an issue where the **Dashboard** did not display the release dates for Application Version, Threat Version, and Antivirus Version.
|
||||
|
||||
## PAN-123167
|
||||
|
||||
Fixed an issue where a process (mprelay) stopped responding.
|
||||
|
||||
## PAN-122788
|
||||
|
||||
Fixed an issue where the firewall incorrectly logged target filenames when an antivirus signature was triggered over a Server Message Block (SMB) protocol.
|
||||
|
||||
## PAN-122779
|
||||
|
||||
Fixed an issue where the firewall did not respond to TCP DNS requests when the firewall acted as a DNS proxy.
|
||||
|
||||
## PAN-122778
|
||||
|
||||
Fixed an issue where the routing daemon restarted due to a deadlock on the path monitoring heartbeat processing, leading to a SIGABRT.
|
||||
|
||||
## PAN-122565
|
||||
|
||||
Fixed an issue where a log collector with a dynamically assigned IP address could not establish communication between other log collectors.
|
||||
|
||||
## PAN-122455
|
||||
|
||||
Fixed an issue where the DHCP server incorrectly processed bootp unicast flag requests.
|
||||
|
||||
## PAN-122311
|
||||
|
||||
Fixed an issue where parent sessions were dropped when you installed duplicate predict session.
|
||||
|
||||
## PAN-122181
|
||||
|
||||
```caveat
|
||||
PA-3200 Series and PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall did not capture inbound Encapsulating Security Payload (ESP) protocol 50 packets at the receive stage.
|
||||
|
||||
## PAN-121917
|
||||
|
||||
```caveat
|
||||
PA-800 Series and PA-220 firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the hrProcessorLoad.2 OID displayed incorrect values.
|
||||
|
||||
## PAN-121827
|
||||
|
||||
Fixed an issue where allow lists and auth profiles in multi-vsys systems would not allow a user to be identified in user groups.Users would show as **Not in allow list** because the multi-vsys (vsys1) was shown as **vsys0**.
|
||||
|
||||
## PAN-121609
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls using PA-7000-20G-NPC cards only
|
||||
```
|
||||
|
||||
Fixed an issue where the firewall restarted due to an internal path monitoring heartbeat failure during periods of more than expected traffic load.
|
||||
|
||||
## PAN-121484
|
||||
|
||||
```caveat
|
||||
PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the dataplane sent positive acknowledgments to predict-status checks from FPP when the corresponding predict was deleted, which caused SIP and RTSP applications to perform less than the expected achievable performance.
|
||||
|
||||
## PAN-121481
|
||||
|
||||
Fixed an issue where downloading the GlobalProtect app software on your GlobalProtect portal took longer than expected.
|
||||
|
||||
## PAN-121472
|
||||
|
||||
Fixed an intermittent issue where the dataplane stopped responding when processing compressed traffic.
|
||||
|
||||
## PAN-121374
|
||||
|
||||
Fixed an issue where Internet Protocol (IP) tags with timeouts generated alert messages.
|
||||
|
||||
## PAN-121184
|
||||
|
||||
Fixed an issue where the varrcvr process crashed due to memory corruption issues.
|
||||
|
||||
## PAN-121058
|
||||
|
||||
A fix was made to address a DOM-based cross site scripting vulnerability in the PAN-OS and Panorama management web interfaces ([CVE-2020-2017](https://security.paloaltonetworks.com/CVE-2020-2017)).
|
||||
|
||||
## PAN-121022
|
||||
|
||||
Fixed an issue involving unexpected behavior within the GlobalProtect app where the Active viewed Template does not populate when clicking the hyperlink to trigger a redirect to the Template area and list.
|
||||
|
||||
## PAN-120986
|
||||
|
||||
Fixed an issue where a process (routed) stopped responding when you configured virtual interfaces.
|
||||
|
||||
## PAN-120965
|
||||
|
||||
Fixed an issue where certificate revocation list (CRL) and Online Certificate Status Protocol (OCSP) checks did not respond as expected when you configured **Block session if certificate status is unknown**.
|
||||
|
||||
## PAN-120909
|
||||
|
||||
Fixed an issue to improve the validation of certain field inputs in the web interface.
|
||||
|
||||
## PAN-120900
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where after you submitted a host information profile (HIP) report a duplicate User-ID™ log was generated on the passive firewall.
|
||||
|
||||
## PAN-120893
|
||||
|
||||
Fixed an issue where the Security Parameter Index (SPI) size was incorrectly set in the IKE Phase 2 packet when you configured commit-bit on the neighboring device, which caused IKE negotiations to fail on the neighboring device.
|
||||
|
||||
## PAN-120730
|
||||
|
||||
Fixed an issue where pushing a config bundle from Panorama M-Series to a firewall failed with the following error: log-card -> iptag unexpected here.
|
||||
|
||||
## PAN-120701
|
||||
|
||||
Fixed an issue where URL filtering blocked web traffic by the security policy that did not have URL filtering enabled.
|
||||
|
||||
## PAN-120665
|
||||
|
||||
(PA-800 Series) Fixed an issue where the deployment of the Master Key through the web interface failed.
|
||||
|
||||
## PAN-120545
|
||||
|
||||
Fixed an issue on VM-Series firewalls where the ager ran faster than expected, which prematurely caused the master key to expire.
|
||||
|
||||
## PAN-120420
|
||||
|
||||
Fixed an issue in Panorama where you could not see **Certificate Profile** in the drop-down when adding an HTTP Server Profile.
|
||||
|
||||
## PAN-120397
|
||||
|
||||
A fix was made to address an external control of path and data vulnerability in the Palo Alto Networks Panorama XSLT processing logic ([CVE-2020-2001](https://security.paloaltonetworks.com/CVE-2020-2001)).
|
||||
|
||||
## PAN-120351
|
||||
|
||||
Fixed an issue where the firewall caused unnecessary fragmentation when traffic and tunnel were content inspected, which caused retransmission and slowed response time.
|
||||
|
||||
## PAN-120300
|
||||
|
||||
Fixed an issue where you were unable to view DHCP leases from the web interface or through the show dhcp server lease interface all CLI command due to the request taking longer than expected, which resulted in a time out.
|
||||
|
||||
## PAN-120157
|
||||
|
||||
Fixed an issue where temporary files created on a firewall during an API call execution were not properly cleaned up, leading to increased disk space usage.
|
||||
|
||||
## PAN-120106
|
||||
|
||||
Fixed an issue where Panorama did not send correlation events and logs to the syslog server after you upgraded the firewall from PAN-OS 8.0.9 to PAN-OS 8.1.7.
|
||||
|
||||
## PAN-120005
|
||||
|
||||
Fixed an issue where the firewall incorrectly forwarded incomplete and corrupted files through the Server Message Block (SMB) protocol to WildFire. This fix requires content release version 8219 or a later version.
|
||||
|
||||
## PAN-119950
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where a process (flow_ctrl) received and restarted due to a malformed ICMPv6 neighbor advertisement packet.
|
||||
|
||||
## PAN-119922
|
||||
|
||||
Fixed an issue in Panorama where the show config diff command was not working correctly and produced unexpected output.
|
||||
|
||||
## PAN-119822
|
||||
|
||||
Fixed an issue where you were not redirected to the application URL after authentication.
|
||||
|
||||
## PAN-119820
|
||||
|
||||
Fixed an issue where the firewall incorrectly calculated the TCP segment size when performing forward proxy decryption.
|
||||
|
||||
## PAN-119819
|
||||
|
||||
Fixed an issue where **Discover** (**Device > User Identification > User Mapping > Server Monitoring**) stopped responding after you configured a DNS proxy.
|
||||
|
||||
## PAN-119818
|
||||
|
||||
Fixed an issue where corrupt logs caused buffered log forwarding to stop responding.
|
||||
|
||||
## PAN-119801
|
||||
|
||||
Fixed an issue where the firewall web interface did not display the BGP **MED** attribute value in the BGP **Rib-Out** tab (**Virtual Routers > More Runtime Stats**).
|
||||
|
||||
## PAN-119550
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where communication between two processes (mgmtsrvr and logd) stopped responding.
|
||||
|
||||
## PAN-119545
|
||||
|
||||
Fixed an issue where updates (including WildFire, antivirus, and so on) were intermittently failing.
|
||||
|
||||
## PAN-119452
|
||||
|
||||
An enhancement was made to improve subsequent loading times of device groups after the first load.
|
||||
|
||||
## PAN-119349
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where custom reports from the User-ID log displayed the incorrect receive date.
|
||||
|
||||
## PAN-119343
|
||||
|
||||
Fixed an issue where a daemon (dnsproxy) incorrectly handled TCP requests, which caused the daemon (dnsproxy) to stop responding.
|
||||
|
||||
## PAN-119047
|
||||
|
||||
Fixed an issue where local user group names that contained upper case characters were not converted to lower case characters prior to encoding, which caused the firewall not to load user groups names with upper case characters.
|
||||
|
||||
## PAN-119046
|
||||
|
||||
Fixed an issue where moving multiple rules in Panorama using the **Move All rules in Group** and **Move rules in group to different rule base** group actions caused the rules to move in a reversed order.
|
||||
|
||||
## PAN-118991
|
||||
|
||||
Fixed an issue in Panorama where on a high availability (HA) pair working in legacy mode, the following error message displayed in the system log: Panorama has lost connection to its peer, no log will be forwarded.
|
||||
|
||||
## PAN-118957
|
||||
|
||||
A fix was made to address an authentication bypass spoofing vulnerability in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS ([CVE-2020-2002](https://security.paloaltonetworks.com/CVE-2020-2002)).
|
||||
|
||||
## PAN-118851
|
||||
|
||||
Fixed an issue where the BGP Conditional Advertisement suppress condition was not met, which caused the **Conditional Adv** (**Network > Virtual Routers > <router-name> > BGP**) not to apply the NEXT HOPS prefix range.
|
||||
|
||||
## PAN-118777
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/active configuration where larger than expected packets sizes were silently dropped when traversing through an HA3 link in an asymmetric network.
|
||||
|
||||
## PAN-118436
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where applications using the GlobalProtect Clientless VPN did not respond when the Clientless VPN used a VLAN interface.
|
||||
|
||||
## PAN-118413
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the show system logd-quota CLI command did not display the Session log storage Quotas as expected.
|
||||
|
||||
## PAN-118259
|
||||
|
||||
Fixed an issue where you were unable to generate WildFire analysis reports in the WildFire Submissions log when you configured **Proxy Server** (**Device > Setup > Services > Global**).
|
||||
|
||||
## PAN-118249
|
||||
|
||||
Fixed an issue where traffic logs and URL Filtering logs did not display the URL for decrypted traffic.
|
||||
|
||||
## PAN-118207
|
||||
|
||||
Fixed an issue where the Security Assertion Markup Language (SAML) for GlobalProtect did not respond as expected when you configured the IdP certificate as **None** on the SAML IdP server profile.
|
||||
|
||||
## PAN-118108
|
||||
|
||||
Fixed an issue where an API call against a Panorama management server, which triggered the request analyze-shared-policy command, caused Panorama to reboot after you executed the command.
|
||||
|
||||
## PAN-118091
|
||||
|
||||
Fixed an issue where application dependency warnings were displayed after a commit when the policy rules containing the dependent applications used different sources (one used user and the other used groups).
|
||||
|
||||
## PAN-118090
|
||||
|
||||
Fixed an issue on Panorama M-Series and virtual appliances where **User Activity Report** (**Monitor > PDF Reports**) did not generate reports as expected.
|
||||
|
||||
## PAN-118075
|
||||
|
||||
Fixed an issue where the BGP conditional advertisement did not respond as expected, which caused the prefix in the **Advertise Filters** (**Network > Virtual Router > BGP > Conditional Adv**) to be incorrectly advertised.
|
||||
|
||||
## PAN-118050
|
||||
|
||||
Fixed an issue where some packets had incorrect timestamps in the transmit stage during packet capture.
|
||||
|
||||
## PAN-117987
|
||||
|
||||
Fixed an issue where the firewall did not exclude video traffic from the GlobalProtect tunnel when you configured **Exclude video traffic from the tunnel (Windows and macOS only)** (**Network > GlobalProtect > Gateways > <gateway-name> > Agent > Video Traffic**).
|
||||
|
||||
## PAN-117969
|
||||
|
||||
An enhancement was made to enable administrators to select signature and digest algorithms for outgoing Security Assertion Markup Language (SAML) messages through a CLI command.
|
||||
|
||||
## PAN-117774
|
||||
|
||||
Fixed an Issue where the dataplane stopped responding due to an incorrect parsing of cookies for GlobalProtect Clientless VPN applications.
|
||||
|
||||
## PAN-117736
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/active configuration where virtual MAC addresses pushed from Panorama were overridden on the local firewall.
|
||||
|
||||
## PAN-117561
|
||||
|
||||
Fixed an issue in Panorama where **Packet Capture** was enabled with **extended-capture** (**Objects > Security Profiles > Anti-Spyware**) for DNS signatures, but the setting was not pushed to firewalls running PAN-OS 8.1.
|
||||
|
||||
## PAN-117479
|
||||
|
||||
A fix was made to address a vulnerability with the Nginx web server included with PAN-OS ([CVE-2017-7529](https://security.paloaltonetworks.com/CVE-2017-7529)).
|
||||
|
||||
## PAN-117463
|
||||
|
||||
Fixed an issue where the firewall did not release the default DHCP route when a new IP address was obtained on a DHCP configured interface.
|
||||
|
||||
## PAN-117446
|
||||
|
||||
Fixed an issue where GlobalProtect authentication failed when you used the domain in the group mapping and a User Principle Name (UPN) format for authentication.
|
||||
|
||||
## PAN-117276
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/active configuration where the names of the virtual routers were pushed from the active-primary firewall to the active-secondary firewall when you sync the configuration, which caused schema verification to stop responding when you do a local commit on the active-secondary firewall.
|
||||
|
||||
## PAN-117251
|
||||
|
||||
Fixed an issue where vsysadmins were unable to view the locks on all the virtual systems they were assigned to. To view the locks in CLI run the new show commit-locks vsys and show config-locks vsys CLI commands.
|
||||
|
||||
## PAN-117167
|
||||
|
||||
Fixed an issue where a process (configd) exceeded the memory limit and stopped responding.
|
||||
|
||||
## PAN-116889
|
||||
|
||||
Fixed an issue where you were unable to establish an SSH session through a CLI command using a Diffie-Hellman (DH) algorithm.
|
||||
|
||||
## PAN-116841
|
||||
|
||||
Fixed an issue where commits failed when address objects were used in static route configurations.
|
||||
|
||||
## PAN-116615
|
||||
|
||||
Fixed an issue where authentication failed for newly added groups in the authentication profile Allow List.
|
||||
|
||||
## PAN-116383
|
||||
|
||||
Fixed an issue with Panorama on AWS where the configuration of the high availability (HA) pair became out of sync due to different plugin versions being detected even though the same versions were installed on both peers.
|
||||
|
||||
## PAN-116355
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue on a firewall in a high availability (HA) active/passive configuration where an HA1 heartbeat backup connection flap occurred and displayed the following error message: ha_ping_send/No buffer space available.
|
||||
|
||||
## PAN-116173
|
||||
|
||||
Fixed an intermittent issue on a firewall in a high availability (HA) active/passive configuration where traffic interruptions occurred until you triggered a manual failover.
|
||||
|
||||
## PAN-116100
|
||||
|
||||
Fixed an issue where a process (mprelay) stopped responding and invoked an out-of-memory (OOM) killer condition and displayed the following error messages: tcam full and pan_plfm_fe_cp_arp_delete.
|
||||
|
||||
## PAN-115875
|
||||
|
||||
Fixed an issue where a PA-7080b HA pair rebooted when large sized packet traffic impacted the front panel ports of the Log Forwarding Card (LFC).
|
||||
|
||||
## PAN-115238
|
||||
|
||||
Fixed an issue where SSL renegotiation sessions incorrectly identified URL categories.
|
||||
|
||||
## PAN-115018
|
||||
|
||||
Fixed an issue where the firewall was unable to access the CPU information and caused the CPU frequency to set to 0, which resulted in a divide by zero error and caused a process (devsrvr) to stop responding.
|
||||
|
||||
## PAN-114966
|
||||
|
||||
Fixed an issue where trunk interfaces were not working on Hyper-V.
|
||||
|
||||
## PAN-114784
|
||||
|
||||
Fixed an issue where a process (devsrvr) stopped responding after you pushed a configuration from Panorama to a firewall.
|
||||
|
||||
## PAN-114438
|
||||
|
||||
Fixed an issue where the system log incorrectly reported intermittent certificate revocation list (CRL) fetches as successful even though the fetches were not successful.
|
||||
|
||||
## PAN-114197
|
||||
|
||||
Fixed an issue where a configured certificate profile was not visible from the web interface in **Network > Network Profiles > IKE Gateways > Add > General > Certificate Profile**.
|
||||
|
||||
## PAN-113144
|
||||
|
||||
Fixed an issue where BGP peers were not enabled when transitioning from Active/Passive to Active/Active or Active/Active to Active/Passive config on both IPv4 and IPv6 peer groups.
|
||||
|
||||
## PAN-112145
|
||||
|
||||
Fixed an intermittent issue where a process (useridd) incorrectly reported successful Ops commands and did not download Dynamic Address Group updates, which prevented virtual machines from updating Dynamic Address Groups.
|
||||
|
||||
## PAN-111650
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) stopped responding when another process (masterd) sent a signal interruption after you upgraded from a PAN-OS 9.0 release to a PAN-OS 9.1 release.
|
||||
|
||||
## PAN-111333
|
||||
|
||||
An enhancement was made to increase the pattern match limit to recognize applications and threats accurately.
|
||||
|
||||
## PAN-111135
|
||||
|
||||
Fixed an issue where Panorama displayed incorrect device monitoring values (**Panorama > Managed Devices > Health**) for the firewall.
|
||||
|
||||
## PAN-109528
|
||||
|
||||
Fixed an issue where an old GPRS tunneling protocol (GTP) event was unexpectedly freed when an update message arrived, causing a crash.
|
||||
|
||||
## PAN-109406
|
||||
|
||||
Fixed an issue where the firewall restarted when you unplugged the QSFP+ module from the High Speed Chassis Interconnect (HSCI) port.
|
||||
|
||||
## PAN-108992
|
||||
|
||||
A fix was made to address an improper authorization vulnerability in PAN-OS ([CVE-2020-1998](https://security.paloaltonetworks.com/CVE-2020-1998)).
|
||||
|
||||
## PAN-107358
|
||||
|
||||
Fixed an issue where a firewall had a race condition in the error handling code in the write thread, causing memory corruption in the sslmgr session cache ring buffer.
|
||||
|
||||
## PAN-105763
|
||||
|
||||
An enhancement was made to enable you to set the signing algorithm to **sha-1** or **sha-256** in the Security Assertion Markup Language (SAML) message on the firewall.
|
||||
|
||||
## PAN-100946
|
||||
|
||||
Fixed an issue where VM-Series firewalls were unable to support the maximum number of tunnel interfaces due to less than expected memory allocation.
|
||||
|
||||
## PAN-95651
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where incomplete core dump files were generated during dataplane process crashes, making the crash analysis difficult.
|
||||
|
||||
## PAN-71148
|
||||
|
||||
Fixed an issue on Panorama where the **ACC** tab would not show data for the period before the daylight saving time (DST) change.
|
||||
@@ -0,0 +1,465 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.7
|
||||
---
|
||||
|
||||
## WF500-5185
|
||||
|
||||
```caveat
|
||||
WF-500 Series only
|
||||
```
|
||||
|
||||
Fixed an issue where high disk use was observed due to an inadequate rotation of log files.
|
||||
|
||||
## PAN-140090
|
||||
|
||||
Fixed an issue where HA links were down in VLAN access mode for KVM. This fix is only applicable for KVM deployments that are configured in VLAN access mode with SR-IOV.
|
||||
|
||||
## PAN-137458
|
||||
|
||||
Fixed an issue where system logs with new event IDs caused a memory leak in a process (mgmtsrvr).
|
||||
|
||||
## PAN-136698
|
||||
|
||||
Fixed an issue where a process (all_pktproc) stopped responding and the dataplane restarted when the firewall processed a malformed GPRS tunneling protocol (GTP) packet.
|
||||
|
||||
## PAN-136696
|
||||
|
||||
Fixed an issue where the dataplane restarted due to excessive logs from the pan_comm process.
|
||||
|
||||
## PAN-135703
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the switch ports connected to Quad Small Form-factor Pluggable (QSFP+) interfaces were up while Network Processing Cards (NPCs) were still rebooting.
|
||||
|
||||
## PAN-135260
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls running PAN-OS® 8.1.12 only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where the dataplane process (all_pktproc_X) on a Network Processing Card (NPC) restarted when processing IPSec tunnel traffic.
|
||||
|
||||
## PAN-135103
|
||||
|
||||
A fix was made to address a format string vulnerability on PA-7000 Series firewalls with a Log Forwarding Card (LFC) ([CVE-2020-1992](https://security.paloaltonetworks.com/CVE-2020-1992)).
|
||||
|
||||
## PAN-135089
|
||||
|
||||
Fixed an issue where the CPU for a process (ikemgr) spiked when third-party VPN clients connected to the GlobalProtect gateway with more than three DNS servers configured.
|
||||
|
||||
## PAN-134678
|
||||
|
||||
```caveat
|
||||
PA-5200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the Quad Small Form-factor Pluggable (QSFP) 28 ports 21 and 22 did not respond when plugged in with a Finisar 100G AOC cable.
|
||||
|
||||
## PAN-134370
|
||||
|
||||
Fixed an issue where a process (mp-relay) restarted due to missing routes or next hops.
|
||||
|
||||
## PAN-134244
|
||||
|
||||
Fixed an issue where connections proxied by the firewall (such as SSL Decryption, GlobalProtect portal and gateway connections, and SIP over TCP) failed due to insufficient buffer allocation. Some connections failed with the following error message: proxy decrypt failure.
|
||||
|
||||
## PAN-133582
|
||||
|
||||
Fixed an issue in the firewalls where some Dynamic Address Groups pushed from Panorama were missing member IP addresses.
|
||||
|
||||
## PAN-133440
|
||||
|
||||
Fixed an issue where fragmented traffic caused high dataplane use and firewall performance issues.
|
||||
|
||||
## PAN-133378
|
||||
|
||||
Fixed an issue in Panorama where a process (configd) restarted while doing a commit using a RADIUS super admin role.
|
||||
|
||||
## PAN-133048
|
||||
|
||||
```caveat
|
||||
PA-5200 and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls processed traffic asymmetrically when using Internet Protocol (IP) classifiers on virtual wire (vwire) subinterfaces.
|
||||
|
||||
## PAN-133042
|
||||
|
||||
```caveat
|
||||
PA-5200 and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls dropped certain GPRS tunneling protocol (GTP) traffic even when gtp nodrop was enabled.
|
||||
|
||||
## PAN-133040
|
||||
|
||||
Fixed an issue on a WF-500 appliance where a VM-Series firewall controller stopped responding, which caused the appliance to stop file analysis.
|
||||
|
||||
## PAN-131993
|
||||
|
||||
Fixed an issue where a process (reportd) would crash while running a log query.
|
||||
|
||||
## PAN-131907
|
||||
|
||||
Fixed an issue where GPRS tunneling protocol (GTP) version 2 handling was unable to handle fully qualified tunnel endpoint IDs (FTEID) received in reverse order, which resulted in GTP-C and GTP-U flows with incorrect IP addresses and tunnel endpoint IDs (TEID). This caused a GTP stateful inspection failure for subsequent packets on the respective flows.
|
||||
|
||||
## PAN-131486
|
||||
|
||||
Fixed an issue where autocommits failed due to invalid access routes after an upgrade.
|
||||
|
||||
## PAN-131193
|
||||
|
||||
Fixed an issue where firewalls dropped generic routing encapsulation (GRE) packets with the following error message: Packet dropped, prepend failure.
|
||||
|
||||
## PAN-130573
|
||||
|
||||
Fixed an issue where the software pool for Regex results was depleted and caused connection failures.
|
||||
|
||||
## PAN-130447
|
||||
|
||||
Fixed an issue where the firewall dropped offloaded traffic every time there was an explicit commit (**Commit** on the firewall locally or **Commit All Changes** in Panorama) or an implicit commit (such as an Antivirus update, Dynamic Update, or WildFire® update) on the firewall.
|
||||
|
||||
## PAN-130361
|
||||
|
||||
A fix was made to address an external control of filename vulnerability in the SD-WAN component of Palo Alto Networks Panorama ([CVE-2020-2009](https://security.paloaltonetworks.com/CVE-2020-2009)).
|
||||
|
||||
## PAN-130345
|
||||
|
||||
Fixed an issue where the Panorama VM rebooted while filtering for configuration logs when the query value was not one of the predefined string results.
|
||||
|
||||
## PAN-130290
|
||||
|
||||
Fixed an issue in the web interface where traffic logs did not display the destination zone (**Monitor > Logs > Traffic > To Zone**) for multicast sessions.
|
||||
|
||||
## PAN-130262
|
||||
|
||||
Fixed an issue where firewalls dropped HTTP 200 OK messages during the offload of traffic for App-ID™ inspection.
|
||||
|
||||
## PAN-130229
|
||||
|
||||
Fixed an issue on Panorama appliances where you could not change maximum transmission unit (MTU) values from the web interface; attempting to do so caused the appliance to display the following error message: Malformed Request.
|
||||
|
||||
## PAN-129518
|
||||
|
||||
Fixed an issue where the firewall restarted due to an out-of-memory (OOM) condition caused by a leak in a process (ikemgr).
|
||||
|
||||
## PAN-129490
|
||||
|
||||
Fixed an issue where CRL/OCSP verifications failed due to requests routing through the management interface even when service route was configured.
|
||||
|
||||
## PAN-128908
|
||||
|
||||
If a user password was changed but no commit was performed afterward, the new password did not persist after a reboot. Instead, the user could still use the old password to log in, and the calculation of expiry days was incorrect based on the password change timestamp in the database.
|
||||
|
||||
## PAN-128717
|
||||
|
||||
Fixed an issue in Panorama where, after switching context to a managed device, the session idle timeout was not updated, and the web session timed out even while the administrator was actively working in the interface.
|
||||
|
||||
## PAN-127616
|
||||
|
||||
Fixed an issue where you could not push **FQDN Minimum Refresh Time** from Panorama to managed firewalls.
|
||||
|
||||
## PAN-127438
|
||||
|
||||
Fixed an issue where GlobalProtect portal configuration selection based on certificate template OID failed.
|
||||
|
||||
## PAN-127219
|
||||
|
||||
Fixed an issue where you could not select existing certificates when creating an authentication profile by using the Security Assertion Markup Language (SAML) method on the template stack.
|
||||
|
||||
## PAN-127118
|
||||
|
||||
A fix was made to address an OS command line injection vulnerability in the PAN-OS management server where authenticated users were able to inject arbitrary shell commands with root privileges ([CVE-2020-2014](https://security.paloaltonetworks.com/CVE-2020-2014)).
|
||||
|
||||
## PAN-127087
|
||||
|
||||
Fixed an issue where a push operation (**Commit All Changes**) from Panorama failed on passive firewalls when pushing a large number of new Security policy rules to both firewalls in a high availability (HA) pair.
|
||||
|
||||
## PAN-126944
|
||||
|
||||
Fixed an issue where the Panorama Template did not allow for **Ethernet Interface Link Speed** configurations greater than 1,000Mpbs.
|
||||
|
||||
## PAN-126817
|
||||
|
||||
Fixed an issue where Security Assertion Markup Language (SAML) response validation failed with a certificate mismatch error even if the firewall had the same certificate on IdP.
|
||||
|
||||
## PAN-126775
|
||||
|
||||
```caveat
|
||||
PA-800 and PA-220 Series only
|
||||
```
|
||||
|
||||
Fixed an issue where NTP sync failures occurred when using NTP servers configured with IPv6.
|
||||
|
||||
## PAN-126573
|
||||
|
||||
Fixed an issue on Panorama where, after overriding a Layer 3 **Aggregate Group** subinterface, all subinterfaces in the stack template disappeared.
|
||||
|
||||
## PAN-126412
|
||||
|
||||
Fixed an issue where hardware security model (HSM) authentication from the web interface failed if the password contained an ampersand (&).
|
||||
|
||||
## PAN-126362
|
||||
|
||||
A fix was made to address a command injection vulnerability in the PAN-OS management interface where an authenticated administrator was able to execute arbitrary OS commands with root privileges ([CVE-2020-2010](https://security.paloaltonetworks.com/CVE-2020-2010)).
|
||||
|
||||
## PAN-126278
|
||||
|
||||
Fixed an issue where a burst of VLAN-tagged packets in a congested system caused an overflow and locked up the firewall. With this fix, the threshold is increased.
|
||||
|
||||
## PAN-126202
|
||||
|
||||
Fixed an issue where a process (routed) stopped responding when users accessed the web interface to view the OSPF interface data (**Network > Virtual Routers > More Runtime Stats > OSPF > Interface**) if OSPF MD5 was configured in the OSPF Auth profile.
|
||||
|
||||
## PAN-126017
|
||||
|
||||
Fixed an issue where the set application dump on rule CLI command did not accept rule names with more than than 32 characters despite a stated limit of 63 characters.
|
||||
|
||||
## PAN-126014
|
||||
|
||||
Fixed an issue for GlobalProtect gateways where the **Login At** and **Logout At** time fields in the **Previous User** PDF/CSV report for **User Information** used the Epoch standard for displaying time.
|
||||
|
||||
## PAN-125889
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where auto-tagging in log forwarding didn't work.
|
||||
|
||||
## PAN-125804
|
||||
|
||||
A fix was made to address an issue where an OS command injection vulnerability in the PAN-OS management server allowed authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode ([CVE-2020-2028](https://security.paloaltonetworks.com/CVE-2020-2028)).
|
||||
|
||||
## PAN-125546
|
||||
|
||||
Fixed an issue where a process failed to restart even when the system logs displayed the following message: virtual memory exceeded, restarting.
|
||||
|
||||
## PAN-125527
|
||||
|
||||
Fixed an issue where a multilayer ZIP file inspection caused software buffer corruption and the all_pktproc process to restart.
|
||||
|
||||
## PAN-125306
|
||||
|
||||
Fixed an issue where a Transmission Control Protocol (TCP) connection reuse was incorrectly handled by an HA active/active cluster with asymmetric flows.
|
||||
|
||||
## PAN-125194
|
||||
|
||||
Fixed an issue where system startup failed when the collector group was configured with an incorrect serial number of invalid length.
|
||||
|
||||
## PAN-125032
|
||||
|
||||
Fixed an issue where, when **Minimum Password Complexity** was **Enabled** for all local administrators, the setting was also applied to plugin users. This caused API calls from plugin users to fail (HTTP Error code 502) because the password change was not made for the users which caused authentication to fail.
|
||||
|
||||
## PAN-124857
|
||||
|
||||
Fixed an issue where a Microsoft Access Database (MDB) file stopped and a process (mgmtsrvr) stopped responding at the epoll_wait () system call after the Panorama Virtual Appliance was stopped and started from Azure.
|
||||
|
||||
## PAN-124802
|
||||
|
||||
Fixed an issue where LACP connectivity issues were observed due to high CPU utilization when multiple dataplanes were used.
|
||||
|
||||
## PAN-124628
|
||||
|
||||
Fixed an issue where REST API queries were unable to pull shared region objects on Panorama.
|
||||
|
||||
## PAN-124495
|
||||
|
||||
Fixed an issue on Panorama where the task manager showed locally executed jobs but did not show tasks or jobs pushed to managed firewalls.
|
||||
|
||||
## PAN-124087
|
||||
|
||||
Fixed an issue where GPRS tunneling protocol (GTP) v2 protocol handling failed to handle the secondary Modify Bearer Request/Response in the GTP-C session.
|
||||
|
||||
## PAN-123858
|
||||
|
||||
Fixed an issue on firewalls where a process (userid) restarted while processing incorrect IP address-to-username mappings that contained blank usernames from User-ID agents.
|
||||
|
||||
## PAN-123830
|
||||
|
||||
Fixed an issue where the GlobalProtect™ portal used an outdated getbootstrap version.
|
||||
|
||||
## PAN-123736
|
||||
|
||||
Fixed an issue where a Create Session Request message looped internally, which caused continuous packet inspection that consumed firewall resources.
|
||||
|
||||
## PAN-123724
|
||||
|
||||
Fixed an issue in Panorama where shared address objects were not configurable as a destination in a static route configuration.
|
||||
|
||||
## PAN-123391
|
||||
|
||||
A fix was made to address a predictable temporary file vulnerability in PAN-OS ([CVE-2020-1994](https://security.paloaltonetworks.com/CVE-2020-1994)).
|
||||
|
||||
## PAN-123295
|
||||
|
||||
Fixed an issue where the dataplane restarted due to a race condition when a configuration push and a Netflow update occurred simultaneously.
|
||||
|
||||
## PAN-123135
|
||||
|
||||
Fixed an issue where user group membership lookup failed if the username source (for example, Security Assertion Markup Language identity provider (SAML IdP)) did not provide the user domain information. The issue occurred even if you configured the firewall to **Allow matching usernames without domains** (**Device > User Identification > User Mapping > Palo Alto Networks User-ID Agent Setup**).
|
||||
|
||||
## PAN-122909
|
||||
|
||||
Fixed an issue where enabling **SSL Forward Proxy** using the hardware security module (HSM) led to intermittent failures when loading random secure websites and displayed the following message: ERR_CERT_INVALID. This issue was most closely associated with servers presenting ECDSA certificates.
|
||||
|
||||
## PAN-122872
|
||||
|
||||
Fixed an issue where the Aggregate Ethernet (AE) subinterface showed a different status from the AE parent interface.
|
||||
|
||||
## PAN-122147
|
||||
|
||||
Fixed an issue where the firewall dropped IPv6 Bidirectional Forwarding Detection (BFD) packets due to a race condition with the Neighbor Discovery Protocol (NDP).
|
||||
|
||||
## PAN-121822
|
||||
|
||||
Fixed an issue with certificate authentication where only the topmost certificate was used to validate the client certificate.
|
||||
|
||||
## PAN-121654
|
||||
|
||||
```caveat
|
||||
PA-3000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where decrypting HTTP/2 traffic caused performance issues due to low memory conditions.
|
||||
|
||||
## PAN-121626
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an intermittent issue where firewalls dropped packets, which caused issues such as traffic latency, slow file transfers, reduced throughput, internal path monitoring failures, and application failures.
|
||||
|
||||
## PAN-121598
|
||||
|
||||
Fixed an issue where the PAN-OS XML API packet capture (pcap) export failed with the following error message: Missing value for parameter device_name. Now, device_name and sessionid are no longer required parameters.
|
||||
|
||||
## PAN-121596
|
||||
|
||||
Fixed an issue where the OSPF protocol didn't choose the correct loopback address for the forwarding address in the Not-So-Stubby Area (NSSA).
|
||||
|
||||
## PAN-121483
|
||||
|
||||
Fixed an issue where Data Filtering profiles did not generate a packet capture (pcap) for Server Message Block (SMB) when action was set to Alert.
|
||||
|
||||
## PAN-121395
|
||||
|
||||
Fixed an issue where the bidirectional static NAT policy rule hit count did not increase even when the policy was used.
|
||||
|
||||
## PAN-121371
|
||||
|
||||
Fixed an issue where autocommit stopped at 99% if the firewall had an invalid customer ID.
|
||||
|
||||
## PAN-121319
|
||||
|
||||
A fix was made to address a stack-based buffer overflow vulnerability in the management server component of PAN-OS ([CVE-2020-1990](https://security.paloaltonetworks.com/CVE-2020-1990)).
|
||||
|
||||
## PAN-121258
|
||||
|
||||
Fixed an issue where some SSLv3 session traffic logs showed an Allow action even when the security rule policy had a Deny action when url-proxy was enabled.
|
||||
|
||||
## PAN-120726
|
||||
|
||||
Fixed an issue where the firewall incorrectly populated the username after the user was served an Anti-Phishing Continue page due to credential phishing detection.
|
||||
|
||||
## PAN-120640
|
||||
|
||||
Fixed an issue where show routing bfd related commands triggered a memory leak in a process (routed).
|
||||
|
||||
## PAN-120350
|
||||
|
||||
Fixed an issue where an Address Resolution Protocol (ARP) broadcast storm overloaded the Log Processing Card (LPC) and caused the device to reboot.
|
||||
|
||||
## PAN-119810
|
||||
|
||||
A fix was made to address the improper restriction of the XML external entity (XXE) vulnerability in the Palo Alto Networks Panorama management server ([CVE-2020-2012](https://security.paloaltonetworks.com/CVE-2020-2012)).
|
||||
|
||||
## PAN-119625
|
||||
|
||||
Fixed an issue where configuring GlobalProtect certificate enrollment using Simple Certificate Enrollment Protocol (SCEP) with a dynamic SCEP challenge caused the firewall to initiate a TLS 1.0 based connection for challenge authentication.
|
||||
|
||||
## PAN-119442
|
||||
|
||||
Fixed an issue where Panorama did not display the drop-down for part of a custom report after using **Pick up Later** (**Monitor > Manage Custom Reports**).
|
||||
|
||||
## PAN-119173
|
||||
|
||||
```caveat
|
||||
PA-5000 and PA-3000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the passive device in a high availability (HA) pair started processing traffic, which resulted in a packet buffer leak.
|
||||
|
||||
## PAN-118226
|
||||
|
||||
A fix was made to address an improper input validation vulnerability in the configuration daemon of Palo Alto Networks Panorama ([CVE-2020-2011](https://security.paloaltonetworks.com/CVE-2020-2011)).
|
||||
|
||||
## PAN-117480
|
||||
|
||||
A fix was made to upgrade Nginx software included with PAN-OS ([PAN-SA-2020-0006](https://security.paloaltonetworks.com/PAN-SA-2020-0006) / CVE-2016-4450 and CVE-2013-0337).
|
||||
|
||||
## PAN-117108
|
||||
|
||||
Fixed an issue where user mappings populated by the XML API were lost after a reboot.
|
||||
|
||||
## PAN-117043
|
||||
|
||||
Fixed an issue where using special characters in the tag names of the Security policy rules returned the following error message when committing or pushing a configuration: group-tag is invalid.
|
||||
|
||||
## PAN-116842
|
||||
|
||||
Fixed an issue where, after enabling a Cortex Data Lake license, the management plane memory utilization would increase unexpectedly when some connections between the firewall and Customer Support Portal server were blocked, leading to multiple process restarts due to an out-of-memory (OOM) condition.
|
||||
|
||||
## PAN-116231
|
||||
|
||||
Fixed an issue where invalid packet header content drop counters were seen in global counters when packets from the network or HA3 were hitting a stale flow. The following flow state verify error was seen: flow_fpga_rcv_key_err - Packets dropped.
|
||||
|
||||
## PAN-116061
|
||||
|
||||
Fixed an issue where traffic traversing through an IPSec tunnel used did not use the default maximum interface bandwidth, which caused the traffic to traverse through the IPSec tunnel with latency.
|
||||
|
||||
## PAN-116002
|
||||
|
||||
Fixed an issue where an incorrect optimization could cause IP address-to-user mapping to not update within 60 seconds.
|
||||
|
||||
## PAN-115562
|
||||
|
||||
Fixed an issue where superuser CLI permissions for role-based administrators did not match superuser privileges.
|
||||
|
||||
## PAN-115093
|
||||
|
||||
Fixed an issue where the firewall generated excessive logs for content decoder (CTD) errors.
|
||||
|
||||
## PAN-114648
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where the HA1 hearbeat backup connection flapped due to ping failures caused by unavailable buffer space when **Heartbeat Backup** was configured (**Device > High Availability > Election Settings**).
|
||||
|
||||
## PAN-111636
|
||||
|
||||
A fix was made to address OpenSSH issues ([PAN-SA-2020-0002](https://security.paloaltonetworks.com/PAN-SA-2020-0002) / CVE-2018-20685, CVE-2019-6109, and CVE-2019-6111).
|
||||
|
||||
## PAN-102682
|
||||
|
||||
A fix was made to address an OS command injection vulnerability in the management component of PAN-OS where an authenticated user was able to potentially execute arbitrary commands with root privileges ([CVE-2020-2007](https://security.paloaltonetworks.com/CVE-2020-2007)).
|
||||
|
||||
## PAN-100734
|
||||
|
||||
A fix was made to address a buffer flow vulnerability in the PAN-OS management interface where authenticated users were able to crash system processes or execute arbitrary code with root privileges ([CVE-2020-2015](https://security.paloaltonetworks.com/CVE-2020-2015)).
|
||||
|
||||
## PAN-100415
|
||||
|
||||
A fix was made to address an external control of filename vulnerability in the command processing of PAN-OS ([CVE-2020-2003](https://security.paloaltonetworks.com/CVE-2020-2003)).
|
||||
|
||||
## PAN-74442
|
||||
|
||||
Fixed an issue where, after enabling debugging on the dataplane, the debug logs contained information about unrelated traffic.
|
||||
@@ -0,0 +1,201 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.8
|
||||
---
|
||||
|
||||
## PAN-140575
|
||||
|
||||
Fixed an issue where a process (masterd) did not restart another process (logrcvr) on the Log Forwarding Card (LFC) after the process (logrcvr) crashed.
|
||||
|
||||
## PAN-140509
|
||||
|
||||
Fixed an issue where performing private data resets during custom Amazon Machine Image (AMI) creation removed CloudWatch directories and caused the CloudWatch plugin to fail.
|
||||
|
||||
## PAN-140270
|
||||
|
||||
Added additional debugging to periodically collect the debug dataplane internal pdt bcm counters graphical CLI command's output in the Tech Support File (TSF).
|
||||
|
||||
## PAN-140043
|
||||
|
||||
```caveat
|
||||
PA-7050 firewalls running on PA-7000 100G NPCs only
|
||||
```
|
||||
|
||||
Fixed an issue where the PA-7000 100G NPC Native Implemented Function (NIF) initialization took longer than expected, which caused internal path monitoring failure and sent the firewall into a non-functional state while rebooting.
|
||||
|
||||
## PAN-139555
|
||||
|
||||
Fixed an issue where after upgrading the passive firewall, the outer UDP sessions synced from the active firewall did not retain the rule information and after failover, GPRS tunneling protocol (GTP) inspection did not work.
|
||||
|
||||
## PAN-137673
|
||||
|
||||
Fixed an issue where a memory leak associated with a process (devsrvr) caused an out-of-memory (OOM) condition on the firewall.
|
||||
|
||||
## PAN-136765
|
||||
|
||||
Fixed an issue where an FQDN update that resolved to the same IP address of another FQDN across different policies caused the other FQDN to be deleted due to missing FQDN aggregation.
|
||||
|
||||
## PAN-136612
|
||||
|
||||
Fixed an issue where fragmented packets leaked, which caused the depletion of Work Query Entry (WQE) pools.
|
||||
|
||||
## PAN-136470
|
||||
|
||||
Fixed an issue where a process (all_pktproc) restarted while processing packets with 0.0.0.0 and destination protocol 251 that internally mapped to GTP-C traffic, which caused the dataplane to restart.
|
||||
|
||||
## PAN-136173
|
||||
|
||||
Fixed an issue where dataplane interfaces remained down after active firewall bootup or a high availability (HA) failover.
|
||||
|
||||
## PAN-135909
|
||||
|
||||
Fixed an issue where connections to the web interface were abruptly interrupted due to a double free condition (gPanUiPhpGlobal_secure_config_reset), which led to unexpected process restarts.
|
||||
|
||||
## PAN-134571
|
||||
|
||||
Fixed an issue where DNS security incorrectly set bits to zero on compressed DNS packets, which caused DNS malformation.
|
||||
|
||||
## PAN-134547
|
||||
|
||||
Fixed an issue where the passive firewall in an active/passive HA configuration deleted BGP-learned routes synchronized from the active firewall if the BGP configuration included the redistribution of the learned routes.
|
||||
|
||||
## PAN-134546
|
||||
|
||||
Fixed a rare issue on the firewall where a process (flow_mgmt) restarted due to an invalid packet received through the GlobalProtect agent or clientless VPN.
|
||||
|
||||
## PAN-134431
|
||||
|
||||
Fixed an issue with Security Assertion Markup Language (SAML) authentication where the firewall used old authd_id values, which resulted in failed authentication.
|
||||
|
||||
## PAN-133289
|
||||
|
||||
Fixed an issue where improper parsing of the URL database caused high device-server CPU usage.
|
||||
|
||||
## PAN-132898
|
||||
|
||||
Fixed an intermittent issue where logs were missing with log_index debug messages due to merging of the index.
|
||||
|
||||
## PAN-132651
|
||||
|
||||
Fixed an issue where packet buffer use was at 99% and tunnel monitoring failed, which caused tunnel flaps and LDAP authentication failures.
|
||||
|
||||
## PAN-131922
|
||||
|
||||
Fixed an issue where the certificate was not automatically pushed to the firewall until you manually fetched the certificate from the firewall.
|
||||
|
||||
## PAN-131517
|
||||
|
||||
Fixed an issue with a memory corruption error that caused a process (all_pktproc) to restart.
|
||||
|
||||
## PAN-130750
|
||||
|
||||
Fixed an issue where commit failed on the firewall after disabling **Pre-Defined Reports** from Panorama.
|
||||
|
||||
## PAN-129328
|
||||
|
||||
Fixed an issue where packet descriptor (on-chip) usage reached 100% even though buffers, throughput, and session counts were not elevated.
|
||||
|
||||
## PAN-129289
|
||||
|
||||
Fixed an issue where export failed for a large running-config.xml file using the XML API.
|
||||
|
||||
## PAN-128568
|
||||
|
||||
Fixed a rare issue on the firewalls where a process (pan_task) restarted due to NULL pointer exception.
|
||||
|
||||
## PAN-128330
|
||||
|
||||
Fixed an issue where the response for the XML API call for the show object registered-ip all operational CLI command included extra appended content.
|
||||
|
||||
## PAN-128195
|
||||
|
||||
Fixed an issue on Panorama where processes (vld) ran on high CPU when the incoming system log rate was 0.
|
||||
|
||||
## PAN-127614
|
||||
|
||||
Fixed an issue where SNMPv3 monitoring of the firewall failed from the Zabbix server after a firewall reboot or SNMP daemon restart on the firewall.
|
||||
|
||||
## PAN-127358
|
||||
|
||||
Fixed an issue with a memory leak in a process (configd) where virtual memory exceeded the limit, which caused the process to restart.
|
||||
|
||||
## PAN-127318
|
||||
|
||||
Fixed an issue where the firewall intermittently dropped DNS A or AAAA queries received over IPSec tunnels due to a session installation failure.
|
||||
|
||||
## PAN-127004
|
||||
|
||||
Fixed an issue where a process (sysd) restarted due to missing heartbeats.
|
||||
|
||||
## PAN-126205
|
||||
|
||||
Fixed an issue where role-based administrators were unable to import certificate private keys onto firewalls.
|
||||
|
||||
## PAN-126069
|
||||
|
||||
Fixed an issue in Panorama where logs couldn't be viewed when an additional log collector was configured in the existing log collector group.
|
||||
|
||||
## PAN-125934
|
||||
|
||||
Fixed an issue on Panorama where a commit failed when bootstrapping a firewall to a configuration with a serial number of "unknown." The commit failed with the following error message: mgt-config -> devices -> unknown unknown is invalid.
|
||||
|
||||
## PAN-125794
|
||||
|
||||
Fixed an issue where a role-based administrator with CLI access was not able to successfully execute the commit-partial CLI command to commit only changes made by themselves.
|
||||
|
||||
## PAN-125730
|
||||
|
||||
Fixed an issue where packets tagged with IP protocol 252 were incorrectly treated as GPRS tunneling protocol (GTP) traffic, which caused the packet processor to terminate.
|
||||
|
||||
## PAN-125534
|
||||
|
||||
```caveat
|
||||
PA-5200 Series and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where firewalls experienced high packet descriptor (on-chip) usage during uploads to the WildFire Cloud or WF-500 appliance.
|
||||
|
||||
## PAN-125410
|
||||
|
||||
Fixed an issue where a new GPRS tunneling protocol version 2 control plane (GTPv2-C) session reused GTP-C tunnel parameters within two seconds after deleting the old GTP-C session, which caused a session conflict on the firewall.
|
||||
|
||||
## PAN-124893
|
||||
|
||||
Fixed an issue where a race condition caused the FIB entry list to form a circle, which in turn caused a process (mprelay) to infinitely loop.
|
||||
|
||||
## PAN-124039
|
||||
|
||||
A fix was made to address an issue where the GlobalProtect Portal feature in PAN-OS did not set a new session identifier after a successful user login ([CVE-2020-1993](https://security.paloaltonetworks.com/CVE-2020-1993)).
|
||||
|
||||
## PAN-123637
|
||||
|
||||
```caveat
|
||||
PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where configuring 1G small form-factor pluggable (SFP) ports on a firewall with forced speed mode (of 1G) enabled made the link unusable when forced speed mode (of 1G) was also enabled on the peer firewall.
|
||||
|
||||
## PAN-122408
|
||||
|
||||
```caveat
|
||||
PA-7000b Series firewalls with LFC cards only
|
||||
```
|
||||
|
||||
Fixed an issue where the system logs would continuously report a failure to connect to the proxy for WildFire even when the connectivity was working properly.
|
||||
|
||||
## PAN-119806
|
||||
|
||||
Fixed an issue in an HA configuration where the dataplane restarted due to internal packet path monitoring failure on the passive firewall.
|
||||
|
||||
## PAN-116480
|
||||
|
||||
Fixed an issue in Panorama where the show system search-engine-quota CLI command, the show log-collector serial-number <log-collector_SN> CLI command, and **Statistics** (**Panorama > Managed Collectors > Statistics**) showed incorrect log retention data.
|
||||
|
||||
## PAN-111611
|
||||
|
||||
Fixed an issue where the connection between the firewall and Cortex Data Lake flapped if connections decreased.
|
||||
|
||||
## PAN-88136
|
||||
|
||||
Fixed a rare issue where a URL update caused the dataplane to restart.
|
||||
@@ -0,0 +1,9 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.9-h1
|
||||
---
|
||||
|
||||
## PAN-150172
|
||||
|
||||
Fixed an issue where dataplane processes restarted when attempting to access websites that had the NotBefore attribute less than or equal to Unix Epoch Time in the server certificate with forward proxy enabled.
|
||||
@@ -0,0 +1,441 @@
|
||||
---
|
||||
type: Addressed
|
||||
product: PAN-OS
|
||||
version: 9.0.9
|
||||
---
|
||||
|
||||
## WF500-5320
|
||||
|
||||
Fixed an issue where the WF-500 cluster did not synchronize verdicts after successful verdict recheck queries with the WildFire global cloud.
|
||||
|
||||
## PAN-148988
|
||||
|
||||
A fix was made to address a Security Assertion Markup Language (SAML) authentication issue ([CVE-2020-2021](https://security.paloaltonetworks.com/CVE-2020-2021)).
|
||||
|
||||
## PAN-148068
|
||||
|
||||
Fixed an issue where SSL connections were blocked if you enabled decryption with the option to block sessions that have expired certificates. This issue included servers that sent an expired AddTrust certificate authority (CA) in the certificate chain.
|
||||
|
||||
## PAN-145195
|
||||
|
||||
```caveat
|
||||
and PAN-145149
|
||||
```
|
||||
|
||||
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||
|
||||
## PAN-145151
|
||||
|
||||
```caveat
|
||||
and PAN-145149
|
||||
```
|
||||
|
||||
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||
|
||||
## PAN-145150
|
||||
|
||||
```caveat
|
||||
and PAN-145149
|
||||
```
|
||||
|
||||
A fix was made to address a buffer overflow vulnerability in PAN-OS that allowed an unauthenticated attacker to disrupt system processes and potentially execute arbitrary code with root privileges by sending a malicious request to the Captive Portal or Multi-Factor Authentication interface ([CVE-2020-2040](https://security.paloaltonetworks.com/CVE-2020-2040)).
|
||||
|
||||
## PAN-145026
|
||||
|
||||
Fixed an issue where Cortex Data Lake certificates on the firewall were not automatically renewed after the certificates expired.
|
||||
|
||||
## PAN-144882
|
||||
|
||||
Fixed an issue where the firewall generated critical system logs: Fsck failed for Logging Raid Disk Pair after downgrading from PAN-OS 9.0 to PAN-OS 8.1.
|
||||
|
||||
## PAN-144782
|
||||
|
||||
Fixed an issue where a configuration audit created a large number of opresult.out files, which filled up the session/pan/user_tmp directory in opt/pancfg. This caused a slow Panorama response until a device restart was performed or the files were manually deleted from the root of the device.
|
||||
|
||||
## PAN-144646
|
||||
|
||||
Fixed an issue where a process (varrcvr) stopped responding on the PA-7000 Series Log Forwarding Card (LFC) when it received a verdict from the WildFire cloud.
|
||||
|
||||
## PAN-143957
|
||||
|
||||
Fixed an issue where, after loading a saved configuration snapshot by API, a custom role-based administrator required Superuser privileges to perform a full commit.
|
||||
|
||||
## PAN-143648
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls in Azure environment only
|
||||
```
|
||||
|
||||
Fixed an issue where a kernel panic in a Linux Integration Services (LIS) driver caused the firewall to reboot by itself.
|
||||
|
||||
## PAN-141563
|
||||
|
||||
Fixed an issue where Slot 8 path monitoring failure occurred due to a memory buildup in a process (logrcvr) that was caused by slow communication and connection between log forwarding and Cortex Data Lake.
|
||||
|
||||
## PAN-140846
|
||||
|
||||
Fixed an issue where the dataplane restarted during a commit when **Netflow** was enabled.
|
||||
|
||||
## PAN-140494
|
||||
|
||||
Added a mechanism to detect corrupted or incorrect formats received on dataplane CPU. Such packets are dropped, and a counter, pkt_recv_bad_group, is incremented.
|
||||
|
||||
## PAN-140465
|
||||
|
||||
```caveat
|
||||
VM-Series firewalls only
|
||||
```
|
||||
|
||||
Fixed connection issues between IPv6 peers when the IPv6 neighbor cache was synchronized in an HA cluster where, after failover, the newly active firewall did not send multicast neighbor solicitation from its global unicast address.
|
||||
|
||||
## PAN-140386
|
||||
|
||||
Fixed an intermittent issue where the firewall used IP addresses instead of domain names for URL category lookup after upgrading to 9.0.6.
|
||||
|
||||
## PAN-139935
|
||||
|
||||
Fixed an issue in the URL process where a process (devsrvr) stopped responding.
|
||||
|
||||
## PAN-139764
|
||||
|
||||
Fixed an issue where an out-of-memory (OOM) condition occurred due to a memory leak, which caused a process (configd) to restart.
|
||||
|
||||
## PAN-139718
|
||||
|
||||
Fixed an issue where the firewall failed stateful inspection for GTP forward relocation requests greater than 1,500 bytes and could not parse Access Point Name (APN) information in forward relocation requests.
|
||||
|
||||
## PAN-139587
|
||||
|
||||
```caveat
|
||||
PA-5200 Series and PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where high and continuous CPU utilization was seen on dataplanes after IPSec Encapsulating Security Payload (ESP) rekeying occurred for multiple tunnels.
|
||||
|
||||
## PAN-139391
|
||||
|
||||
Fixed an issue where unique GlobalProtect portal profiles were not selected in the correct order.
|
||||
|
||||
## PAN-138870
|
||||
|
||||
Fixed an issue where a process (configd) restarted and administrators received one of the following error messages: Timed out while getting config lock. Please try again or Please wait while the server reboots... due to a database error.
|
||||
|
||||
## PAN-138813
|
||||
|
||||
Fixed a performance drop issue seen when using API to configure larger sets of objects (more than 25 objects).
|
||||
|
||||
## PAN-138739
|
||||
|
||||
Fixed an issue where, in a high availability (HA) active/active configuration in a virtual wire deployment with asymmetric traffic, decryption did not work for some sites.
|
||||
|
||||
## PAN-138476
|
||||
|
||||
Fixed an intermittent issue where logs were delayed or missing when querying for logs by applying filters. To leverage this fix, you must upgrade Panorama to 9.0.9 and the Cloud Services plugin to 1.6.0-h1.
|
||||
|
||||
## PAN-137966
|
||||
|
||||
Fixed a configuration lock issue where Panorama timed out due to a process (configd) being unable to read another process (mongod).
|
||||
|
||||
## PAN-137902
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where hot swapping a PA-7000 100G NPC with a PA-7000 20G NPC caused packet buffer leak and slot restarts.
|
||||
|
||||
## PAN-137867
|
||||
|
||||
```caveat
|
||||
PA-7000 Series firewalls only, running with both a PA-7000 100G NPC and a PA-7000 20G NPC
|
||||
```
|
||||
|
||||
Fixed an issue where IPSec traffic caused dataplane restarts.
|
||||
|
||||
## PAN-137387
|
||||
|
||||
Fixed an issue where URL filtering used the IP address instead of the hostname, which led to incorrect URL categorization.
|
||||
|
||||
## PAN-137138
|
||||
|
||||
Fixed an issue where a process (configd) consistently restarted with the following error message: virtual memory limit exceeded, restarting due to a dynamic updates push from Panorama to multiple firewalls.
|
||||
|
||||
## PAN-136703
|
||||
|
||||
```caveat
|
||||
PA-3000 Series and PA-800 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue with insufficient memory allocation for configurations to accommodate the PAN-OS 9.0 Dynamic Address Group feature.
|
||||
|
||||
## PAN-136649
|
||||
|
||||
Fixed an issue where PA-7000 20GXM and PA-7000 20GQXM Network Processing Cards (NPCs) failed to process some sessions for Layer 7 inspection due to internal maximum threshold value that was not set.
|
||||
|
||||
## PAN-136608
|
||||
|
||||
Fixed an issue in Panorama where the Security policy **Target** displayed the serial number of the targeted device instead of the hostname.
|
||||
|
||||
## PAN-136390
|
||||
|
||||
```caveat
|
||||
PA-7000 Series with 100GB NPC only
|
||||
```
|
||||
|
||||
Fixed an issue during firewall bootup where the following error message: Bootloader upgrade failed, ret 255 appeared when small form-factor pluggable (SFP) modules were installed.
|
||||
|
||||
## PAN-135865
|
||||
|
||||
Fixed an issue that prevented Panorama from being switched out of management-only mode when deployed in Amazon Web Services (AWS) instance types M5 and C5.
|
||||
|
||||
## PAN-135684
|
||||
|
||||
Fixed an issue with log collectors on Panorama where large index sizes caused higher CPU usage than expected when disk space usage was high.
|
||||
|
||||
## PAN-135587
|
||||
|
||||
Fixed an issue where the GlobalProtect gateway was unable to parse a large list of IP addresses assigned on a local machine.
|
||||
|
||||
## PAN-135039
|
||||
|
||||
Fixed an issue in Panorama where a memory leak occurred during an HA sync commit.
|
||||
|
||||
## PAN-134309
|
||||
|
||||
Fixed an issue where a process (devsrvr) restarted when it hit the limit of the number of custom patterns available in the allocated memory.
|
||||
|
||||
## PAN-133731
|
||||
|
||||
Fixed an issue on the Panorama Virtual Appliance where the show interface all CLI command did not list any output.
|
||||
|
||||
## PAN-133727
|
||||
|
||||
Fixed an issue where Session Initiation Protocol (SIP) messages were not parsed correctly when the packet was received in separate segments, which caused the receiver to receive corrupted messages.
|
||||
|
||||
## PAN-133614
|
||||
|
||||
Fixed an issue on the Panorama Virtual Appliance where SNMP Object IDs (OIDs) were missing for interfaces other than the **Management** interface.
|
||||
|
||||
## PAN-133495
|
||||
|
||||
Fixed an issue where the Terminal Server (TS) Agent disconnected on the firewall after a failover or reboot.
|
||||
|
||||
## PAN-133411
|
||||
|
||||
Fixed an issue where after making configuration changes and selecting **Preview Changes**, a 500 Internal Server Error message displayed due to a memory leak.
|
||||
|
||||
## PAN-133211
|
||||
|
||||
Fixed an issue where the policy order was not maintained when moved to a different device group.
|
||||
|
||||
## PAN-132995
|
||||
|
||||
```caveat
|
||||
PA-7000 Series and PA-3200 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where when jumbo frames were enabled, the maximum transmission unit (MTU) size limit was lower than expected.
|
||||
|
||||
## PAN-132766
|
||||
|
||||
Fixed an issue in Panorama where custom region objects were not visible in the GlobalProtect Portal **External Gateway** drop-down.
|
||||
|
||||
## PAN-132712
|
||||
|
||||
Fixed an issue where scheduled reports did not run on a PA-7000 Series firewall not managed by Panorama after upgrade to 8.1.10 or 9.0.4 and later versions.
|
||||
|
||||
## PAN-132476
|
||||
|
||||
Made improvements to the log storage for VM-Series for NSX Panorama.
|
||||
|
||||
## PAN-131945
|
||||
|
||||
Fixed an issue where **Device > VM-Series** on the firewall web interface showed a blank screen.
|
||||
|
||||
## PAN-131792
|
||||
|
||||
Fixed an issue where the **Name** log filter (**Monitor > Logs > Traffic**) was not maintained when viewing the **Log Viewer** for a Security policy rule (**Policies > Security**) from the drop-down.
|
||||
|
||||
## PAN-131501
|
||||
|
||||
Fixed an issue when configuring Clientless VPN and executing the portal-getconfig CLI command where user groups were retrieved but were not freed, which caused a memory leak on a process (sslvpn).
|
||||
|
||||
## PAN-131290
|
||||
|
||||
Fixed an issue where reports from Panorama displayed the following messages: Please wait... and Warning: Some of the devices are in High Speed Log Forwarding Mode.
|
||||
|
||||
## PAN-131038
|
||||
|
||||
Fixed an issue on the firewalls where the FIB lookup routing test did not display all available paths on the web interface.
|
||||
|
||||
## PAN-130870
|
||||
|
||||
Fixed an issue where the management plane CPU on the firewall was high due to index generation on summary logs.
|
||||
|
||||
## PAN-130776
|
||||
|
||||
Fixed an issue on Panorama where Applications and Threats content update deployment failed due to the content version date check.
|
||||
|
||||
## PAN-130558
|
||||
|
||||
Fixed an issue on the firewalls where SNMP queries for panZoneTable listed details for only one zone when there were two zones with same names under different virtual systems.
|
||||
|
||||
## PAN-130121
|
||||
|
||||
Fixed an issue in Amazon Web Services (AWS) where Ethernet1/1 failed DHCP renewal after the hour.
|
||||
|
||||
## PAN-129281
|
||||
|
||||
Fixed an issue where a process (useridd) restarted due to a buffer overflow when the time-to-live (TTL) and **Idle Timeout** values were set to **Never**, a timing issue between user group context and a process (sysd) callback, and a group mapping issue when multiple group mappings fetched the same groups with different override domains.
|
||||
|
||||
## PAN-128879
|
||||
|
||||
Fixed an issue where the PAN-OS XML API inject was not working for IP address to user mappings or for the import of software, content, and plugins.
|
||||
|
||||
## PAN-128393
|
||||
|
||||
Fixed an issue where User-ID running on port 5007 responded with the default certificate and participated in mutual authentication after upgrading to PAN-OS 9.0, which exposed the default certificate on the firewall to third-party vulnerability scanners.
|
||||
|
||||
## PAN-128155
|
||||
|
||||
Fixed an issue where system log entries misspelled "client version" as "lient version", which made it difficult for syslog servers to find these entries.
|
||||
|
||||
## PAN-128078
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) stopped responding and was inaccessible through SSH or HTTPS until the firewall was power cycled.
|
||||
|
||||
## PAN-127434
|
||||
|
||||
Fixed an issue where reports for URLs were not generating the correct data output.
|
||||
|
||||
## PAN-127375
|
||||
|
||||
Fixed an issue where a process (rasmgr) restarted multiple times, which caused the firewall to reboot.
|
||||
|
||||
## PAN-127260
|
||||
|
||||
Fixed an issue where the /opt/pancfg partition became full due to a large amount of botnet reports that were not automatically deleted.
|
||||
|
||||
## PAN-125524
|
||||
|
||||
Fixed an issue where the dataplane restarted when many NAT rules were followed by successive commits.
|
||||
|
||||
## PAN-125501
|
||||
|
||||
Fixed an issue where URL information in a URL **Custom Report** was blank when the report contained flexible size fields (such as **URL Category List**).
|
||||
|
||||
## PAN-125466
|
||||
|
||||
Fixed an issue where, during Antivirus or Threat Content update downloads or install, some show commands in the CLI, API calls, and web interface pages gave information output with significant delay (15-60 seconds).
|
||||
|
||||
## PAN-124916
|
||||
|
||||
Added two ciphers for GlobalProtect Portal TLS connections.
|
||||
|
||||
## PAN-123279
|
||||
|
||||
Fixed an issue where a process (configd) stopped responding after upgrading Panorama to 8.1.9 from 8.0.16 due to 8.0 WildFire appliance register requests.
|
||||
|
||||
## PAN-123090
|
||||
|
||||
```caveat
|
||||
PA-3000 Series firewalls only
|
||||
```
|
||||
|
||||
Fixed an issue where a configuration commit failed due to a memory allocation failure on the dataplane.
|
||||
|
||||
## PAN-122226
|
||||
|
||||
Fixed an issue where traffic failed to match Security policies using wildcard address objects.
|
||||
|
||||
## PAN-121602
|
||||
|
||||
Fixed an issue on Panorama where a query (after-change-preview contains) did not return the expected results for configuration logs.
|
||||
|
||||
## PAN-120830
|
||||
|
||||
Fixed an issue in Panorama where certificate import failed with the following error message: Certificate chain cannot be validated, required CAs not found.
|
||||
|
||||
## PAN-120614
|
||||
|
||||
Fixed an issue where a commit from a Panorama appliance running PAN-OS 9.1 to a managed firewall running PAN-OS 9.0 or earlier failed with the following error message in ms.log: error generating tranform ike-pre-transform.xsl.
|
||||
|
||||
## PAN-120454
|
||||
|
||||
Fixed an issue where the firewall did not fail over to the secondary LDAP server when the primary LDAP server was not reachable and the configured LDAP bind timeout was not properly honored when SSL protocol was used.
|
||||
|
||||
## PAN-120113
|
||||
|
||||
Fixed an issue where the **to**, **from**, and **subject** fields did not populate in the threat logs if the fields were out of order.
|
||||
|
||||
## PAN-120105
|
||||
|
||||
Fixed an issue where email header information intermittently was not present in threat logs.
|
||||
|
||||
## PAN-119645
|
||||
|
||||
Fixed an issue where a process (panio) used unnecessary memory and caused an out-of-memory (OOM) condition on the dataplane if the dataplane was already low on memory.
|
||||
|
||||
## PAN-119170
|
||||
|
||||
Fixed an issue where Panorama did not display managed devices when selecting **Revert Content** (**Panorama > Device Deployment > Dynamic Updates**).
|
||||
|
||||
## PAN-119159
|
||||
|
||||
Fixed an issue where if one invalid FQDN object was configured, FQDN resolution failed for all FQDN objects.
|
||||
|
||||
## PAN-118098
|
||||
|
||||
Fixed an issue where a process (useridd) restarted while updating user groups. This issue occurred when multiple group mapping profiles were used to fetch the same group information while using different domain override settings.
|
||||
|
||||
## PAN-117606
|
||||
|
||||
Fixed an issue where a process (configd) crashed while making configuration changes on Panorama.
|
||||
|
||||
## PAN-117487
|
||||
|
||||
Fixed an issue where a process (mgmtsrvr) stopped responding due to a memory corruption issue when acquiring a configuration lock.
|
||||
|
||||
## PAN-117075
|
||||
|
||||
Fixed an issue where the firewall did not process the TLS record in SSL Inbound Inspection as expected, which introduced out-of-order packets in the transmit stage packet capture and affected client performance while accessing HTTP video applications.
|
||||
|
||||
## PAN-116835
|
||||
|
||||
Fixed an issue with log reading performance when using WMI for server monitoring with PAN-OS integrated User-ID agent.
|
||||
|
||||
## PAN-116720
|
||||
|
||||
A fix was made to address a reflected cross-site scripting (XSS) vulnerability in the PAN-OS management web interface where, if a remote attacker was able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link, the attacker could execute arbitrary code JavaScript code in the administrator's browser and perform administrative actions ([CVE-2020-2036](https://security.paloaltonetworks.com/CVE-2020-2036)).
|
||||
|
||||
## PAN-115914
|
||||
|
||||
Fixed an issue where Static, Connected, and Host routes were missing on the FIB table of the firewall in a passive state after 300 seconds of switch over.
|
||||
|
||||
## PAN-112120
|
||||
|
||||
Fixed an issue where threat **Name** field of a threat **Custom Report** displayed the threat ID instead of the threat name.
|
||||
|
||||
## PAN-111379
|
||||
|
||||
Fixed an issue on the firewall where the Application Command Center (ACC) **Network Activity** tab displayed the message In Progress and stopped responding.
|
||||
|
||||
## PAN-110457
|
||||
|
||||
Fixed an issue where Panorama ran out of memory due to high memory usage on a process (configd).
|
||||
|
||||
## PAN-106763
|
||||
|
||||
Fixed an issue where the dataplane crashed while freeing up memory due to a corrupted or long certificate field in the handshake.
|
||||
|
||||
## PAN-102202
|
||||
|
||||
Fixed an issue where the OSPF summary Link State Advertisement (LSA) for the default 0.0.0.0/0 route were not advertised by the Area Border Router (ABR).
|
||||
|
||||
## PAN-98933
|
||||
|
||||
Fixed an issue on an M-Series appliances in a high availability (HA) active/passive configuration where the schedules (*Device > Dynamic Updates*) were unresponsive after a failover or restart of Panorama.
|
||||
|
||||
## PAN-98694
|
||||
|
||||
Fixed an issue on a PA-5200 Series firewall in an HA active/passive configuration where the firewall dropped TCP-FIN packets after a failover.
|
||||
Reference in New Issue
Block a user